Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-60685

Опубликовано: 13 нояб. 2025
Источник: nvd
CVSS3: 5.1
EPSS Низкий

Описание

A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function). The binary reads the /proc/stat file using fgets() into a local buffer and subsequently parses the line using sscanf() into a single-byte variable with the %s format specifier. Maliciously crafted /proc/stat content can overwrite adjacent stack memory, potentially allowing an attacker with filesystem write privileges to execute arbitrary code on the device.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:totolink:a720r_firmware:4.1.5cu.614_b20230630:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a720r:-:*:*:*:*:*:*:*

EPSS

Процентиль: 6%
0.00024
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 5.1
github
3 месяца назад

A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function). The binary reads the /proc/stat file using fgets() into a local buffer and subsequently parses the line using sscanf() into a single-byte variable with the %s format specifier. Maliciously crafted /proc/stat content can overwrite adjacent stack memory, potentially allowing an attacker with filesystem write privileges to execute arbitrary code on the device.

CVSS3: 5.1
fstec
4 месяца назад

Уязвимость функции sub_401EE0() микропрограммного обеспечения роутеров TOTOLINK A720R, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 6%
0.00024
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-121