CVE-2025-44837: Command Injection
TOTOLINK CPE CP900 V6.3c.1144B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url or magicid parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44837?
CVE-2025-44837 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2025-44837?
To fix CVE-2025-44837, update the Totolink CPE CP900 device to the latest firmware version that addresses this vulnerability.
What type of vulnerability is CVE-2025-44837?
CVE-2025-44837 is a command injection vulnerability that allows attackers to execute arbitrary commands on the affected device.
What are the potential impacts of CVE-2025-44837?
The potential impacts of CVE-2025-44837 include unauthorized system access, data manipulation, and complete control over the device.
Who is affected by CVE-2025-44837?
Owners of the Totolink CPE CP900 devices running the vulnerable firmware version are at risk due to CVE-2025-44837.