CNNVD-202506-3216 Information
CNNVD ID
CNNVD-202506-3216
Related CVE
- CNNVD Published: 2025-06-25
Description (Chinese)
TOTOLINK CA300-PoE是中国吉翁电子(TOTOLINK)公司的一款无线接入点。 TOTOLINK CA300-PoE 6.2c.884版本存在命令注入漏洞,该漏洞源于文件upgrade.so对参数FileName处理不当,可能导致os命令注入攻击。
Description (English)
TOTOLINK CA300-PoE is a wireless access point for the Chinese company TOTOLINK. TOTOLINK CA300-PoE 6.2c.884 contains a command-injecting loophole, which results from the inappropriate handling of the parameter FileName in documentupgrade.so, which may lead to an Os command-injection attack.
Hazard Level
High
Vulnerability Type
命令注入
Affected Vendor
头歌
Published
2025-06-25
Last Modified
2026-02-24
References
https://vuldb.com/?ctiid.313837 https://www.totolink.net/ https://vuldb.com/?submit.602264 https://vuldb.com/?id.313837 https://github.com/wudipjq/my_vuln/blob/main/totolink4/vuln_45/45.md https://github.com/wudipjq/my_vuln/blob/main/totolink4/vuln_45/45.md#poc https://nvd.nist.gov/vuln/detail/CVE-2025-6619
Share on: