CVE-2025-60702
13.11.2025, 20:15
A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagnosisCfg` function retrieves the `ipDoamin` parameter from user input via `websGetVar` and concatenates it directly into a `ping` system command executed via `CsteSystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.
| Vendor | Product | Version |
|---|---|---|
| totolink | a950rg_firmware | 5.9c.4592_b20191022:c.4592_b20191022 |
𝑥
= Vulnerable software versions