CVE-2025-44838: Command Injection
TOTOLINK CPE CP900 V6.3c.1144B20190715 was discovered to contain a command injection vulnerability in the setUploadUserData function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44838?
CVE-2025-44838 is classified as a high-severity command injection vulnerability.
How do I fix CVE-2025-44838?
To mitigate CVE-2025-44838, update the Totolink CPE CP900 firmware to the latest version provided by the vendor.
What systems are affected by CVE-2025-44838?
CVE-2025-44838 affects the Totolink CPE CP900 running firmware version V6.3c.1144_B20190715.
What type of execution is possible with CVE-2025-44838?
CVE-2025-44838 allows attackers to execute arbitrary commands via the setUploadUserData function.
How can I determine if my device is vulnerable to CVE-2025-44838?
To check for vulnerability to CVE-2025-44838, ensure that your Totolink CPE CP900 is running firmware older than V6.3c.1144_B20190715.