VendorsTOTOLINKca300-poe_firmwareall versions
Vulnerabilities

TOTOLINK ca300-poe Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2025-6621
TOTOLINK CA300-PoE ap.so QuickSetting os command injection
Published 2025-06-25 · Analyzed
9.8EPSS 0.025
CVE-2025-6620
TOTOLINK CA300-PoE upgrade.so setUpgradeUboot os command injection
Published 2025-06-25 · Analyzed
9.8EPSS 0.025
CVE-2025-6619
TOTOLINK CA300-PoE upgrade.so setUpgradeFW os command injection
Published 2025-06-25 · Analyzed
9.8EPSS 0.025
CVE-2025-6618
TOTOLINK CA300-PoE wps.so SetWLanApcliSettings os command injection
Published 2025-06-25 · Analyzed
9.8EPSS 0.025
CVE-2023-24139
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter in the setNetworkDiag function.
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2023-24140
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDiag function.
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2023-24141
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function.
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2023-24142
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag function.
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2023-24143
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetworkDiag function.
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2023-24144
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function.
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2023-24159
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function.
Published 2023-02-14 · Modified
9.8EPSS 0.019
CVE-2023-24161
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.
Published 2023-02-14 · Modified
9.8EPSS 0.019
CVE-2023-24160
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.
Published 2023-02-14 · Modified
9.8EPSS 0.019
CVE-2023-24138
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2023-24146
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the setRebootScheCfg function.
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2023-24148
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData function.
Published 2023-02-03 · Modified
9.8EPSS 0.018
CVE-2023-24145
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function.
Published 2023-02-03 · Modified
9.8EPSS 0.018
CVE-2023-24149
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.
Published 2023-02-03 · Modified
9.8EPSS 0.008
CVE-2024-7217
TOTOLINK CA300-PoE cstecgi.cgi loginauth buffer overflow
Published 2024-07-30 · Modified
8.8EPSS 0.068
CVE-2023-24147
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini.
Published 2023-02-03 · Modified
7.5EPSS 0.007
CVE-2025-44860
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Published 2025-05-01 · Analyzed
6.5EPSS 0.008
CVE-2025-44863
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Published 2025-05-01 · Analyzed
6.5EPSS 0.008
CVE-2025-44861
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Published 2025-05-01 · Analyzed
6.3EPSS 0.009
CVE-2025-44862
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Published 2025-05-01 · Analyzed
6.3EPSS 0.009