Buffer Overflow Vulnerability in TOTOLINK A950RG Router Firmware
CVE-2025-60699
What is CVE-2025-60699?
A buffer overflow vulnerability exists in the firmware of the TOTOLINK A950RG Router, specifically within the global.so binary. The flaw is located in the getSaveConfig function, which retrieves the http_host parameter from user input via websGetVar. This parameter is then copied to a fixed-size stack buffer (v13) using strcpy() without any length validation. Due to this oversight, an unauthenticated remote attacker could exploit the vulnerability by sending specially crafted HTTP requests to the router's web interface, potentially resulting in arbitrary code execution on the device.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
