Totolink
Totolink Cp900 Firmware: vulnerabilidades y CVE
Totolink Cp900 Firmware tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses0
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-44838 | Media (6.3) | 0.94% | — | 1 may 2025 | TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setUploadUserData function via the FileName parameter. This vulnerability allows attackers to execute arbitrary… |
| CVE-2025-44837 | Media (6.3) | 0.94% | — | 1 may 2025 | TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url or magicid parameters. This vulnerability allows attackers to… |
| CVE-2025-44836 | Media (6.3) | 0.94% | — | 1 may 2025 | TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setApRebootScheCfg function via the hour or minute parameters. This vulnerability allows attackers to execute… |
| CVE-2025-44854 | Media (6.3) | 0.94% | — | 1 may 2025 | TOTOLINK CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands… |
| CVE-2024-7464 | Media (5.3) | 20% | — | 5 ago 2024 | A vulnerability, which was classified as critical, has been found in TOTOLINK CP900 6.3c.566. This issue affects the function setTelnetCfg of the component Telnet Service. The manipulation of the argument telnet_enabled… |
| CVE-2024-7463 | Alta (8.7) | 11% | — | 5 ago 2024 | A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to… |
| CVE-2022-28495 | Crítica (9.8) | 2.4% | — | 24 mar 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute… |
| CVE-2022-28496 | Crítica (9.8) | 1.4% | — | 23 mar 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to… |
| CVE-2022-28497 | Crítica (9.8) | 1.4% | — | 23 mar 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute… |
| CVE-2022-28493 | Crítica (9.8) | 0.68% | — | 23 mar 2023 | A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service, |
| CVE-2022-28491 | Crítica (9.8) | 4.7% | — | 23 mar 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands… |
| CVE-2022-28492 | Crítica (9.8) | 1.3% | — | 23 mar 2023 | TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login. |
| CVE-2022-28494 | Crítica (9.8) | 2.6% | — | 23 mar 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerability allows attackers to execute arbitrary… |