CVE-2025-44860: Command Injection
TOTOLINK CA300-POE V6.2c.884B20180522 was found to contain a command injection vulnerability in the msgprocess function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44860?
CVE-2025-44860 is classified as a high-severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2025-44860?
To fix CVE-2025-44860, update to the latest firmware provided by TOTOLINK that addresses the command injection vulnerability.
What type of vulnerability is CVE-2025-44860?
CVE-2025-44860 is a command injection vulnerability that allows attackers to execute arbitrary commands through a crafted request.
Who is affected by CVE-2025-44860?
Devices running TOTOLINK CA300-POE V6.2c.884_B20180522 are affected by CVE-2025-44860.
How can attackers exploit CVE-2025-44860?
Attackers can exploit CVE-2025-44860 by sending specially crafted requests with malicious commands through the Port parameter.