Command Injection Vulnerability in TOTOLINK CPE Products
CVE-2025-44838

Currently unrated

Key Information:

Vendor

TOTOLINK

Status
Vendor
CVE Published:
1 May 2025

What is CVE-2025-44838?

The TOTOLINK CPE CP900 V6.3c.1144_B20190715 is susceptible to a command injection vulnerability found in the setUploadUserData function. This issue manifests when the FileName parameter is improperly validated, allowing attackers to craft malicious requests that can execute arbitrary commands on the device. The exploitation of this vulnerability poses significant security threats to affected users, making it imperative for stakeholders to address the flaw promptly.

References

EPSS Score

15% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.