CVE Details
Basic Information
| Title | TOTOLINK CA300-PoE upgrade.so setUpgradeFW os command injection |
|---|---|
| Type | cve |
| Published | 2025-06-25T17:31:10.779Z |
| Last Seen |
Product Information
| Vendor | TOTOLINK |
|---|---|
| Product | CA300-PoE |
| Version | 6.2c.884 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A vulnerability in TOTOLINK CA300-PoE allows remote attackers to inject OS commands via the FileName argument in the setUpgradeFW function of upgrade.so. This could lead to unauthorized system access and execution of arbitrary commands. |
|---|---|
| AI Severity | High |
| Vendor | TOTOLINK |
| Product | CA300-PoE |
| Affected Version | 6.2c.884 |
Affected Products
- TOTOLINK CA300-PoE 6.2c.884
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-78, CWE-77 |
| Bulletin Family |
References
Description
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. Affected by this vulnerability is the function setUpgradeFW of the file upgrade.so. The manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.