Security Advisory

CVE-2025-60702

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-11-13 00:00:00
Last updated 2025-11-14 16:53:26
Assigner mitre
State PUBLISHED

Description

A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagnosisCfg` function retrieves the `ipDoamin` parameter from user input via `websGetVar` and concatenates it directly into a `ping` system command executed via `CsteSystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the routers web interface.