Command Injection Vulnerability in TOTOLINK CPE Products
CVE-2025-44838

Currently unrated

Key Information:

Vendor

TOTOLINK

Status
Vendor
CVE Published:
1 May 2025

What is CVE-2025-44838?

The TOTOLINK CPE CP900 V6.3c.1144_B20190715 is susceptible to a command injection vulnerability found in the setUploadUserData function. This issue manifests when the FileName parameter is improperly validated, allowing attackers to craft malicious requests that can execute arbitrary commands on the device. The exploitation of this vulnerability poses significant security threats to affected users, making it imperative for stakeholders to address the flaw promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.