PT-2025-18654 · Totolink · Totolink Cp900L

Published

2025-04-05

·

Updated

2025-05-03

·

CVE-2025-44854

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK CP900 version 6.3c.1144 B20190715
Description The issue is related to a command injection vulnerability in the setUpgradeUboot function via the FileName parameter. This allows attackers to execute arbitrary commands via a crafted request.
Recommendations For TOTOLINK CP900 version 6.3c.1144 B20190715, consider disabling the setUpgradeUboot function until a patch is available to prevent exploitation via the FileName parameter.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-06191
CVE-2025-44854

Affected Products

Totolink Cp900L