TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url or magicid parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
2025-05-01T15:16:20.837
2025-05-22T15:29:38.487
Analyzed
CVSSv3.1: 6.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | totolink | cp900_firmware | 6.3c.1144_b20190715 | Yes |
| Hardware | totolink | cp900 | - | No |