github.comrelated
https://github.com/at0de/my_vulns/blob/main/TOTOLINK/A720R/clearDiagnosisLog.md CVE-2025-4269
MEDIUM
TOTOLINK A720R Log cstecgi.cgi access control
Record summary
CVE-2025-4269 has a selected CVSS score of 6.9 (medium).
Description
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi of the component Log Handler. The manipulation of the argument topicurl with the input clearDiagnosisLog/clearSyslog/clearTracerouteLog leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 4.1.5cu.374 | affected |
References
7github.comexploit
https://github.com/at0de/my_vulns/blob/main/TOTOLINK/A720R/clearSyslog.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-4269 VDB-307373 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.307373 VDB-307373 | TOTOLINK A720R Log cstecgi.cgi access controlvdb entryTechnical description
https://vuldb.com/?id.307373 Submit #563430 | TOTOLINK A720R V4.1.5cu.374 Improper Access ControlsThird-party advisory
https://vuldb.com/?submit.563430 totolink.netproduct
https://www.totolink.net/