Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-60682


A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell commands and executed via system() without any sanitization or escaping. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device.


Published

2025-11-13T16:15:52.080

Last Modified

2025-11-17T19:16:58.540

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System totolink a720r_firmware 4.1.5cu.614_b20230630 Yes
Hardware totolink a720r - No

References