PT-2025-18653 · Totolink · Totolink Cpe Cp900

CVE-2025-44838

·

Publicado

2025-04-01

·

Atualizado

2025-05-03

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK CPE CP900 version 6.3c.1144 B20190715
Description A command injection issue was discovered in the setUploadUserData function through the FileName parameter. This issue allows attackers to execute arbitrary commands via a manipulated request.
Recommendations For TOTOLINK CPE CP900 version 6.3c.1144 B20190715, consider disabling the setUploadUserData function until a patch is available to prevent exploitation. Restrict access to the FileName parameter in the affected function to minimize the risk of arbitrary command execution.

Exploit

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-06195
CVE-2025-44838

Produtos afetados

Totolink Cpe Cp900