VendorsTOTOLINKa950rg_firmware5.9c.4592_b20191022
Vulnerabilities

TOTOLINK A950RG Firmware 4.1.2cu.5204 B20210112 5.9c.4592_b20191022

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-60702
A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagnosisCfg` function retrieves the `ipDoamin` parameter from user input via `websGetVar` and concatenates it directly into a `ping` system command executed via `CsteSystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.
Published 2025-11-13 · Analyzed
6.5EPSS 0.025
CVE-2025-60699
A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `global.so` binary. The `getSaveConfig` function retrieves the `http_host` parameter from user input via `websGetVar` and copies it into a fixed-size stack buffer (`v13`) using `strcpy()` without performing any length checks. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted HTTP request to the router's web interface, potentially leading to arbitrary code execution.
Published 2025-11-13 · Analyzed
6.5EPSS 0.008