VYPR
Unrated severityNVD Advisory· Published May 1, 2025· Updated May 1, 2025

CVE-2025-44838

CVE-2025-44838

Description

TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setUploadUserData function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A command injection in TOTOLINK CP900 setUploadUserData via the FileName parameter lets unauthenticated attackers execute arbitrary commands over the network.

Vulnerability

A command injection vulnerability exists in the setUploadUserData function of TOTOLINK CPE CP900 firmware version V6.3c.1144_B20190715. The function retrieves the FileName parameter via websGetVar and passes it unsanitized into a sprintf call that builds a rm -rf command executed by CsteSystem. This allows an attacker to inject arbitrary OS commands by including shell metacharacters in the FileName value [1].

Exploitation

The vulnerability can be triggered remotely over HTTP. An attacker crafts a POST request to /cgi-bin/cstecgi.cgi with a JSON body containing topicurl set to setting/setUploadUserData and FileName set to a value with a command injection payload, such as '1;pwd'. No authentication or prior access is required; the attacker only needs network connectivity to the device's management interface [1].

Impact

Successful exploitation results in arbitrary command execution on the underlying operating system with the privileges of the web server process. This can lead to full device compromise, including disclosure of sensitive data, modification of configuration, or further network attacks [1].

Mitigation

The vendor has not released a patched firmware version as of the publication date (2025-05-01). No workaround is available. Users should consider disabling remote management access or isolating the device from untrusted networks until a fix is provided [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Totolink/CPE CP900cpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: V6.3c.1144_B20190715

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.