CVE-2025-6620: TOTOLINK CA300-PoE upgrade.so setUpgradeUboot os command injection
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been rated as critical. Affected by this issue is the function setUpgradeUboot of the file upgrade.so. The manipulation of the argument FileName leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6620?
CVE-2025-6620 is rated as critical due to its potential for remote command injection.
How can I mitigate CVE-2025-6620?
To mitigate CVE-2025-6620, it is recommended to update the TOTOLINK CA300-PoE firmware to the latest version with security patches.
What systems are affected by CVE-2025-6620?
CVE-2025-6620 specifically affects the TOTOLINK CA300-PoE model.
What type of attack does CVE-2025-6620 facilitate?
CVE-2025-6620 allows for remote OS command injection through manipulation of the FileName argument.
Is there an exploit available for CVE-2025-6620?
Yes, CVE-2025-6620 has known exploits that can be leveraged against vulnerable systems if not patched.