Unauthenticated Command Injection Vulnerability in ToToLink Router
CVE-2025-60687

6.5MEDIUM

Key Information:

Vendor

ToToLink

Vendor
CVE Published:
13 November 2025

What is CVE-2025-60687?

A command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130. This vulnerability allows an attacker to execute arbitrary commands on the router by manipulating the 'imei' parameter in a web request. The firmware fails to properly sanitize the input, only checking for the character length of 15, which can be exploited to inject malicious commands through the cstecgi.cgi binary. This issue highlights the importance of stringent input validation and server-side security measures.

References

EPSS Score

11% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.