Skip to main content

Vendor/product archive

totolink / cp900_firmware CVEs

Beta · best-effort

13 CVEs tagged to totolink / cp900_firmware7 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2025-44838

Published May 1, 2025

TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setUploadUserData function via the FileName parameter. This vulnerabilit…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-44837

Published May 1, 2025

TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url or magicid parameters.…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-44836

Published May 1, 2025

TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setApRebootScheCfg function via the hour or minute parameters. This vuln…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-44854

Published May 1, 2025

TOTOLINK CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName parameter. This vulnerability allows at…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-7464

Published Aug 5, 2024

A vulnerability, which was classified as critical, has been found in TOTOLINK CP900 6.3c.566. This issue affects the function setTelnetCfg of the component Telnet Service. The man…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7463

Published Aug 5, 2024

A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manip…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28495

Published Mar 24, 2023

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerab…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28496

Published Mar 23, 2023

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. Thi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28497

Published Mar 23, 2023

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vul…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28491

Published Mar 23, 2023

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows at…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28494

Published Mar 23, 2023

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerabili…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1