📦 Cp900 Firmware

by Totolink

🔍 What is Cp900 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-28497

CRITICAL CVSS 9.8 Mar 23, 2023

This critical vulnerability in TOTOLink CP900 outdoor CPE devices allows attackers to execute arbitrary commands via command injection in the mtd_write_bootloader function. Attackers can gain complete...

CVE-2022-28491

CRITICAL CVSS 9.8 Mar 23, 2023

This is a critical command injection vulnerability in TOTOLink CP900 outdoor CPE devices that allows unauthenticated attackers to execute arbitrary system commands via the NTPSyncWithHost function. At...

CVE-2022-28492

CRITICAL CVSS 9.8 Mar 23, 2023

CVE-2022-28492 is a critical authentication bypass vulnerability in TOTOLINK CPE devices that allows remote attackers to gain unauthorized access without valid credentials. This affects TOTOLINK Techn...

CVE-2022-28494

CRITICAL CVSS 9.8 Mar 23, 2023

This CVE describes a command injection vulnerability in TOTOLink CP900 outdoor CPE devices that allows attackers to execute arbitrary commands via the filename parameter in the setUpgradeFW function. ...

CVE-2024-7463

HIGH CVSS 8.8 Aug 5, 2024

This critical buffer overflow vulnerability in TOTOLINK CP900 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the UploadCustomModule function. Attack...

CVE-2025-44836

MEDIUM CVSS 6.3 May 1, 2025

This command injection vulnerability in TOTOLINK CP900 routers allows attackers to execute arbitrary system commands by manipulating the hour or minute parameters in the setApRebootScheCfg function. A...

CVE-2025-44838

MEDIUM CVSS 6.3 May 1, 2025

This CVE describes a command injection vulnerability in TOTOLINK CP900 routers that allows attackers to execute arbitrary system commands through the FileName parameter in the setUploadUserData functi...

CVE-2025-44854

MEDIUM CVSS 6.3 May 1, 2025

This CVE describes a command injection vulnerability in TOTOLINK CP900 routers that allows attackers to execute arbitrary system commands via the FileName parameter in the setUpgradeUboot function. At...