Totolink
Totolink Ca300-poe Firmware: vulnerabilidades y CVE
Totolink Ca300-poe Firmware tiene 24 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses0
Críticas14
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-6621 | Baja (2.1) | 2.5% | — | 25 jun 2025 | A vulnerability classified as critical has been found in TOTOLINK CA300-PoE 6.2c.884. This affects the function QuickSetting of the file ap.so. The manipulation of the argument hour/minute leads to os command injection.… |
| CVE-2025-6620 | Baja (2.1) | 2.5% | — | 25 jun 2025 | A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been rated as critical. Affected by this issue is the function setUpgradeUboot of the file upgrade.so. The manipulation of the argument FileName leads to… |
| CVE-2025-6619 | Baja (2.1) | 2.4% | — | 25 jun 2025 | A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. Affected by this vulnerability is the function setUpgradeFW of the file upgrade.so. The manipulation of the argument FileName… |
| CVE-2025-6618 | Baja (2.1) | 2.4% | — | 25 jun 2025 | A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been classified as critical. Affected is the function SetWLanApcliSettings of the file wps.so. The manipulation of the argument PIN leads to os command… |
| CVE-2025-44863 | Media (6.5) | 0.87% | — | 1 may 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a… |
| CVE-2025-44862 | Media (6.3) | 0.94% | — | 1 may 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands… |
| CVE-2025-44861 | Media (6.3) | 0.94% | — | 1 may 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary… |
| CVE-2025-44860 | Media (6.5) | 0.87% | — | 1 may 2025 | TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a… |
| CVE-2024-7217 | Media (5.3) | 7.1% | — | 30 jul 2024 | A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. This vulnerability affects the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password… |
| CVE-2023-24161 | Crítica (9.8) | 1.9% | — | 14 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function. |
| CVE-2023-24160 | Crítica (9.8) | 1.9% | — | 14 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function. |
| CVE-2023-24159 | Crítica (9.8) | 1.9% | — | 14 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function. |
| CVE-2023-24149 | Crítica (9.8) | 0.82% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow. |
| CVE-2023-24148 | Crítica (9.8) | 1.8% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData function. |
| CVE-2023-24147 | Alta (7.5) | 0.66% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini. |
| CVE-2023-24146 | Crítica (9.8) | 1.9% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the setRebootScheCfg function. |
| CVE-2023-24145 | Crítica (9.8) | 1.8% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function. |
| CVE-2023-24144 | Crítica (9.8) | 1.9% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function. |
| CVE-2023-24143 | Crítica (9.8) | 1.9% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetworkDiag function. |
| CVE-2023-24142 | Crítica (9.8) | 1.9% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag function. |
| CVE-2023-24141 | Crítica (9.8) | 1.9% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function. |
| CVE-2023-24140 | Crítica (9.8) | 1.9% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDiag function. |
| CVE-2023-24139 | Crítica (9.8) | 1.9% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter in the setNetworkDiag function. |
| CVE-2023-24138 | Crítica (9.8) | 1.9% | — | 3 feb 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function. |