📦 Ca300 Poe Firmware

by Totolink

🔍 What is Ca300 Poe Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-24159

CRITICAL CVSS 9.8 Feb 14, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands into the admpass parameter. Attackers can gain full control of af...

CVE-2023-24161

CRITICAL CVSS 9.8 Feb 14, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands through the webWlanIdx parameter. Attackers can gain full control...

CVE-2023-24148

CRITICAL CVSS 9.8 Feb 3, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands into the FileName parameter of the setUploadUserData function. At...

CVE-2023-24142

CRITICAL CVSS 9.8 Feb 3, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands into the NetDiagPingSize parameter. Attackers can gain full contr...

CVE-2023-24144

CRITICAL CVSS 9.8 Feb 3, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands into the hour parameter of the setRebootScheCfg function. Attacke...

CVE-2023-24146

CRITICAL CVSS 9.8 Feb 3, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands into the minute parameter of the setRebootScheCfg function. Attac...

CVE-2023-24138

CRITICAL CVSS 9.8 Feb 3, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers via command injection in the NTPSyncWithHost function. Attackers can exploit this by sending spec...

CVE-2023-24140

CRITICAL CVSS 9.8 Feb 3, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious input into the NetDiagPingNum parameter. Attackers can gain full control o...

CVE-2025-6621

MEDIUM CVSS 6.3 Jun 25, 2025

This critical vulnerability in TOTOLINK CA300-PoE routers allows remote attackers to execute arbitrary operating system commands by manipulating time parameters (hour/minute) in the QuickSetting funct...

CVE-2025-6619

MEDIUM CVSS 6.3 Jun 25, 2025

This critical vulnerability in TOTOLINK CA300-PoE routers allows remote attackers to execute arbitrary operating system commands by manipulating the FileName parameter in the firmware upgrade function...

CVE-2025-44860

MEDIUM CVSS 6.5 May 1, 2025

This CVE describes a command injection vulnerability in TOTOLINK CA300-POE routers that allows attackers to execute arbitrary system commands via the Port parameter in the msg_process function. Attack...

CVE-2025-44862

MEDIUM CVSS 6.3 May 1, 2025

This CVE describes a command injection vulnerability in TOTOLINK CA300-POE routers that allows attackers to execute arbitrary system commands via a crafted firmware upgrade request. Attackers can expl...

CVE-2024-7217

MEDIUM CVSS 6.3 Jul 30, 2024

This critical vulnerability in TOTOLINK CA300-PoE routers allows remote attackers to execute arbitrary code via a buffer overflow in the login authentication function. Attackers can exploit this by se...