Advisories

TOTOLINK Command Injection via recvUpgradeNewFw

Go Back
severity
critical
date
Affecting
  • TOTOLINK CA300-POE & CA600-PoE devices

  • An affected hardware/firmware range has yet to be defined

CWE
  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS
9.3
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Summermu
Description
TOTOLINK wireless ceiling mount access point devices firmware version V5.3c.6665_B20180820 and prior contain a command injection vulnerability in the firmware upgrade handling logic. The recvUpgradeNewFw function improperly handles user-supplied input passed via the fwUrl parameter in conjunction with the newSvn parameter without adequate input sanitation. This allows an authenticated attacker to inject and execute arbitrary system commands during the firmware upgrade process. CVE-2025-44846 is potentially a duplicate of CVE-2025-44862. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-01-20 (UTC).

Ready to get Started?

Explore VulnCheck, a next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence to help you prioritize and remediate vulnerabilities that matter.
  • Vulnerability Prioritization
    Prioritize vulnerabilities that matter based on the threat landscape and defer vulnerabilities that don't.
  • Early Warning System
    Real-time alerting of changes in the vulnerability landscape so that you can take action before the attacks start.