CVE-2025-44854: Command Injection
TOTOLINK CP900 V6.3c.1144B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44854?
CVE-2025-44854 is classified as a critical vulnerability due to its ability to allow attackers to execute arbitrary commands.
How do I fix CVE-2025-44854?
To mitigate CVE-2025-44854, update the Totolink CP900 firmware to a patched version provided by the vendor.
What is the impact of CVE-2025-44854?
The impact of CVE-2025-44854 includes unauthorized command execution, potentially leading to full system compromise.
Which products are affected by CVE-2025-44854?
CVE-2025-44854 affects the Totolink CP900 device running version V6.3c.1144_B20190715 firmware.
How can attackers exploit CVE-2025-44854?
Attackers can exploit CVE-2025-44854 by sending a crafted request containing malicious input to the setUpgradeUboot function.