CVE-2025-44862: Command Injection
TOTOLINK CA300-POE V6.2c.884B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44862?
CVE-2025-44862 is classified as a high-severity vulnerability due to its ability to allow command injection.
How do I fix CVE-2025-44862?
To fix CVE-2025-44862, users should update the TOTOLINK CA300-POE to the latest firmware version provided by the manufacturer.
What type of vulnerability is CVE-2025-44862?
CVE-2025-44862 is a command injection vulnerability that affects the recvUpgradeNewFw function.
What is the impact of CVE-2025-44862 on my device?
The impact of CVE-2025-44862 can allow attackers to execute arbitrary commands on the affected device, potentially compromising its security.
Who is affected by CVE-2025-44862?
CVE-2025-44862 affects users of the TOTOLINK CA300-POE running version V6.2c.884_B20180522.