CVE-2025-44861: Command Injection
TOTOLINK CA300-POE V6.2c.884B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44861?
CVE-2025-44861 is classified as a high severity command injection vulnerability.
How does CVE-2025-44861 affect the TOTOLINK CA300-POE?
CVE-2025-44861 allows attackers to execute arbitrary commands on the TOTOLINK CA300-POE by exploiting the CloudSrvUserdataVersionCheck function.
How do I fix CVE-2025-44861?
To fix CVE-2025-44861, ensure that you update the TOTOLINK CA300-POE device firmware to a version that addresses this vulnerability.
Can CVE-2025-44861 be exploited remotely?
Yes, CVE-2025-44861 can be exploited remotely through crafted requests to the device.
What are the potential consequences of exploiting CVE-2025-44861?
Exploiting CVE-2025-44861 can lead to unauthorized command execution, potential system compromise, and data breaches.