In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.
2025-07-21T16:15:29.323
2025-08-07T17:58:19.833
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | a7100ru_firmware | 7.4 | Yes |
Hardware | totolink | a7100ru | - | No |
Operating System | totolink | a950rg_firmware | 5.9 | Yes |
Hardware | totolink | a950rg | - | No |
Operating System | totolink | t10_firmware | 5.9 | Yes |
Hardware | totolink | t10 | - | No |