CNNVD-202511-1608 Information

CNNVD ID

CNNVD-202511-1608

CVE-2025-60682

  • CNNVD Published: 2025-11-13

Description (Chinese)

TOTOLINK A720R是中国吉翁电子(TOTOLINK)公司的一款无线路由器。 TOTOLINK A720R V4.1.5cu.614_B20230630版本存在安全漏洞,该漏洞源于cloudupdate_check二进制文件中magicid和url参数未经验证,可能导致命令注入。

Description (English)

TOTOLINK A720R is a wireless router of the Chinese company TOTOLINK. TOTOLINK A720R V4.1.5cu.614 B20230630 has a security loophole, which originates from the unverified Magicid and url parameters in the cloudupdate check binary file, which may lead to the injection of the command.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

吉翁电子

Published

2025-11-13

Last Modified

2026-02-24

References

http://totolink.com https://github.com/yifan20020708/SGTaint-0-day/blob/main/ToToLink/ToToLink-A720R/CVE-2025-60682.md https://www.totolink.net/ https://access.redhat.com/security/cve/cve-2025-60682

Share on: