cbcvebase.

Totolink Ca300-Poe Firmware vulnerabilities

24 known vulnerabilities affecting totolink/ca300-poe_firmware.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL18HIGH2MEDIUM4

Vulnerabilities

Page 2 of 2
CVE-2025-44861P3MEDIUMCVSS 6.3v6.2c.884_b201805222025-05-01
CVE-2025-44861 [MEDIUM] CWE-77 CVE-2025-44861: TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44860P3MEDIUMCVSS 6.5v6.2c.884_b201805222025-05-01
CVE-2025-44860 [MEDIUM] CWE-77 CVE-2025-44860: TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44863P3MEDIUMCVSS 6.5v6.2c.884_b201805222025-05-01
CVE-2025-44863 [MEDIUM] CWE-77 CVE-2025-44863: TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2023-24147P3HIGHCVSS 7.5v6.2c.8842023-02-03
CVE-2023-24147 [HIGH] CWE-798 CVE-2023-24147: TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service w TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini.
nvd
Totolink Ca300-Poe Firmware vulnerabilities | cvebase