Command Injection Vulnerability in TOTOLINK A950RG Router Firmware
CVE-2025-60702
What is CVE-2025-60702?
A command injection vulnerability has been identified in the firmware of the TOTOLINK A950RG Router. Specifically, the vulnerability resides in the system.so binary, where the setDiagnosisCfg function inadequately handles the ipDomain parameter, sourced from user input via websGetVar. This leads to the parameter being directly concatenated to a ping system command via CsteSystem(), without any input sanitization. An unauthenticated remote attacker could exploit this flaw by sending carefully crafted HTTP requests to the router's web interface, allowing for the execution of arbitrary commands on the device, thereby posing a significant risk to network integrity and user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
