CVE detail
CVE-2025-6618
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been classified as critical. Affected is the function SetWLanApcliSettings of the file wps.so. The manipulation of the argument PIN leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://www.totolink.net/www.totolink.net
No excerpt available.
Productwww.totolink.netJun 25, 2025, 6:15 PM - https://vuldb.com/?submit.602263vuldb.com
No excerpt available.
Exploitvuldb.comJun 25, 2025, 6:15 PM - https://vuldb.com/?id.313836vuldb.com
No excerpt available.
Exploitvuldb.comJun 25, 2025, 6:15 PM - https://vuldb.com/?ctiid.313836vuldb.com
No excerpt available.
Exploitvuldb.comJun 25, 2025, 6:15 PM No excerpt available.
Exploitgithub.comJun 25, 2025, 6:15 PMNo excerpt available.
Exploitgithub.comJun 25, 2025, 6:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- wudipjq/my_vulnHigh confidencegithubNVD Exploit reference0 starsDiscovered Aug 16, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-6621CVSS 2.1 · Low
A vulnerability classified as critical has been found in TOTOLINK CA300-PoE 6.2c.884. This affects the function QuickSetting of the file ap.so. The manipulation of the argument ho…
- CVE-2025-6620CVSS 2.1 · Low
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been rated as critical. Affected by this issue is the function setUpgradeUboot of the file upgrade.so. The manipul…
- CVE-2025-6619CVSS 2.1 · Low
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. Affected by this vulnerability is the function setUpgradeFW of the file upgrade.so. The…
- CVE-2025-44863CVSS 6.5 · Medium
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attacker…
- CVE-2025-44862CVSS 6.3 · Medium
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows a…
- CVE-2025-44861CVSS 6.3 · Medium
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerabilit…