CVE List

CVE-2025-6621

Severe 9.8

A vulnerability classified as critical has been found in TOTOLINK CA300-PoE 6.2c.884. This affects the function QuickSetting of the file ap.so. The manipulation of the argument hour/minute leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Published June 25, 2025.

Affected software

Get alerts for Totolink Ca300-poe Firmware

Reference links