Description

A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagnosisCfg` function retrieves the `ipDoamin` parameter from user input via `websGetVar` and concatenates it directly into a `ping` system command executed via `CsteSystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.

INFO

Published Date :

2025-11-13T00:00:00.000Z

Last Modified :

2025-11-14T16:53:26.753Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-60702 vulnerability.

Vendors Products
Totolink
  • A950rg
  • A950rg Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact