Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-60682

Опубликовано: 13 нояб. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell commands and executed via system() without any sanitization or escaping. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:totolink:a720r_firmware:4.1.5cu.614_b20230630:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a720r:-:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.0173
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 6.5
github
около 1 месяца назад

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell commands and executed via system() without any sanitization or escaping. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device.

CVSS3: 6.5
fstec
2 месяца назад

Уязвимость функции sub_402414() микропрограммного обеспечения роутеров TOTOLINK A720R, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 82%
0.0173
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-77