← Vulnerability feed

Vulnerability record · CVE-2023-24159 · published 14 February 2023

CVE-2023-24159: Totolink ca300-poe firmware command injection vulnerability

TTotolink · Ca300 Poe Firmware

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function.

9.8 CVSS 3.1 Critical EPSS 1.9% · top 20.9% CWE-77 · Command injection
9.8CVSS 3.1 base score
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-24159 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-24160Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.EPSS 1.9%9.8CVE-2023-24161Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.EPSS 1.9%9.8CVE-2023-24148Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData function.EPSS 1.8%9.8CVE-2023-24149Totolink ca300-poe firmware hard-coded credentials vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.EPSS 0.82%9.8CVE-2023-24142Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag func…EPSS 1.9%9.8CVE-2023-24143Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetworkDiag fu…EPSS 1.9%9.8CVE-2023-24144Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function.EPSS 1.9%9.8CVE-2023-24145Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData fu…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2023-24159), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.