PT-2025-18674 · Totolink · Totolink Ca300-Poe

Published

2025-04-05

·

Updated

2025-05-03

·

CVE-2025-44861

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK CA300-POE version 6.2c.884 B20180522
Description A command injection issue was found in the CloudSrvUserdataVersionCheck function via the url parameter, allowing attackers to execute arbitrary commands through a crafted request.
Recommendations For TOTOLINK CA300-POE version 6.2c.884 B20180522, as a temporary workaround, consider restricting access to the CloudSrvUserdataVersionCheck function until a patch is available. Avoid using the url parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-06190
CVE-2025-44861

Affected Products

Totolink Ca300-Poe