CVE-2025-6618: TOTOLINK CA300-PoE wps.so SetWLanApcliSettings os command injection
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been classified as critical. Affected is the function SetWLanApcliSettings of the file wps.so. The manipulation of the argument PIN leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6618?
CVE-2025-6618 is classified as a critical severity vulnerability.
How does CVE-2025-6618 affect TOTOLINK CA300-PoE devices?
CVE-2025-6618 allows for os command injection due to improper handling of the argument PIN in the SetWLanApcliSettings function.
Can CVE-2025-6618 be exploited remotely?
Yes, CVE-2025-6618 can be exploited remotely by an attacker.
What are the potential consequences of exploiting CVE-2025-6618?
Exploiting CVE-2025-6618 may lead to unauthorized command execution on the affected TOTOLINK CA300-PoE device.
How can I mitigate the risks associated with CVE-2025-6618?
To mitigate CVE-2025-6618, ensure that your TOTOLINK CA300-PoE device is updated with the latest firmware from the vendor.