TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
2025-05-01T18:15:56.647
2025-05-21T19:47:17.270
Analyzed
CVSSv3.1: 6.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | ca300-poe_firmware | 6.2c.884_b20180522 | Yes |
Hardware | totolink | ca300-poe | - | No |