Unauthenticated Command Injection Vulnerability in ToToLink Router
CVE-2025-60687
6.5MEDIUM
What is CVE-2025-60687?
A command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130. This vulnerability allows an attacker to execute arbitrary commands on the router by manipulating the 'imei' parameter in a web request. The firmware fails to properly sanitize the input, only checking for the character length of 15, which can be exploited to inject malicious commands through the cstecgi.cgi binary. This issue highlights the importance of stringent input validation and server-side security measures.
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
