Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-60683


A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the sub_40BFA4 function that handles network interface reinitialization from '/var/system/linux_vlan_reinit'. Input is only partially validated by checking the prefix of interface names, and is concatenated into shell commands executed via system() without escaping. An attacker with write access to this file can execute arbitrary commands on the device.


Published

2025-11-13T16:15:52.213

Last Modified

2025-11-17T19:16:33.620

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System totolink a720r_firmware 4.1.5cu.614_b20230630 Yes
Hardware totolink a720r - No

References