CVE-2023-24160: Totolink CA300-Poe Firmware

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.

Affected products

  • Totolink CA300-Poe Firmware: version 6.2c.884 only

Published 2023-02-14. Last modified 2026-06-17.