TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the svn parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
2025-05-01T17:15:50.253
2025-05-22T15:30:14.850
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | totolink | ca600-poe_firmware | 5.3c.6665_b20180820* | Yes |
| Hardware | totolink | ca600-poe | - | No |