Metrics
Affected Vendors & Products
Fri, 27 Jun 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Totolink
Totolink ca300-poe Totolink ca300-poe Firmware |
|
CPEs | cpe:2.3:h:totolink:ca300-poe:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:ca300-poe_firmware:6.2c.884:*:*:*:*:*:*:* |
|
Vendors & Products |
Totolink
Totolink ca300-poe Totolink ca300-poe Firmware |
Wed, 25 Jun 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 25 Jun 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. Affected by this vulnerability is the function setUpgradeFW of the file upgrade.so. The manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
Title | TOTOLINK CA300-PoE upgrade.so setUpgradeFW os command injection | |
Weaknesses | CWE-77 CWE-78 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-25T17:31:10.779Z
Updated: 2025-06-25T17:52:47.782Z
Reserved: 2025-06-25T07:13:55.824Z
Link: CVE-2025-6619

Updated: 2025-06-25T17:52:44.753Z

Status : Analyzed
Published: 2025-06-25T18:15:24.950
Modified: 2025-06-27T18:19:19.447
Link: CVE-2025-6619

No data.