VYPR

CPE CP900

by Totolink

CVEs (12)

  • CVE-2022-28495CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-28496CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-28497CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-28493CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,

  • CVE-2022-28491CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.05

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-28494CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.03

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2024-7463HigAug 5, 2024
    risk 0.58cvss 8.8epss 0.11

    A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack can be initiated remotely. The…

  • CVE-2024-7464MedAug 5, 2024
    risk 0.43cvss 6.3epss 0.20

    A vulnerability, which was classified as critical, has been found in TOTOLINK CP900 6.3c.566. This issue affects the function setTelnetCfg of the component Telnet Service. The manipulation of the argument telnet_enabled leads to command injection. The attack may be initiated…

  • CVE-2025-44838MedMay 1, 2025
    risk 0.41cvss 6.3epss 0.01

    TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setUploadUserData function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44837MedMay 1, 2025
    risk 0.41cvss 6.3epss 0.01

    TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url or magicid parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44836MedMay 1, 2025
    risk 0.41cvss 6.3epss 0.01

    TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setApRebootScheCfg function via the hour or minute parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44854MedMay 1, 2025
    risk 0.41cvss 6.3epss 0.01

    TOTOLINK CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.