Totolink Ca600-Poe Firmware vulnerabilities
10 known vulnerabilities affecting totolink/ca600-poe_firmware.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM10
Vulnerabilities
Page 1 of 1
CVE-2025-44845MEDIUMCVSS 6.5v5.3c.6665_b20180820*2025-05-01
CVE-2025-44845 [MEDIUM] CWE-77 CVE-2025-44845: TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in th
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44848MEDIUMCVSS 6.5v5.3c.6665_b20180820*2025-05-01
CVE-2025-44848 [MEDIUM] CWE-77 CVE-2025-44848: TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in th
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44846MEDIUMCVSS 6.3v5.3c.6665_b20180820*2025-05-01
CVE-2025-44846 [MEDIUM] CWE-77 CVE-2025-44846: TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in th
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44844MEDIUMCVSS 6.5v5.3c.6665_b20180820*2025-05-01
CVE-2025-44844 [MEDIUM] CWE-77 CVE-2025-44844: TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in th
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44847MEDIUMCVSS 6.3v5.3c.6665_b20180820*2025-05-01
CVE-2025-44847 [MEDIUM] CWE-77 CVE-2025-44847: TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in th
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44841MEDIUMCVSS 6.5v5.3c.6665_b20180820*2025-05-01
CVE-2025-44841 [MEDIUM] CWE-77 CVE-2025-44841: TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in th
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the version parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44840MEDIUMCVSS 6.5v5.3c.6665_b20180820*2025-05-01
CVE-2025-44840 [MEDIUM] CWE-77 CVE-2025-44840: TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in th
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the svn parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44839MEDIUMCVSS 6.5v5.3c.6665_b20180820*2025-05-01
CVE-2025-44839 [MEDIUM] CWE-77 CVE-2025-44839: TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in th
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the magicid parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44843MEDIUMCVSS 6.5v5.3c.6665_b20180820*2025-05-01
CVE-2025-44843 [MEDIUM] CWE-77 CVE-2025-44843: TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in th
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44842MEDIUMCVSS 6.5v5.3c.6665_b20180820*2025-05-01
CVE-2025-44842 [MEDIUM] CWE-77 CVE-2025-44842: TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in th
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd