CVE-2025-4269
MEDIUMTOTOLINK A720R 4.1.5cu.374 - Improper Access Controls
Title source: llmDescription
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi of the component Log Handler. The manipulation of the argument topicurl with the input clearDiagnosisLog/clearSyslog/clearTracerouteLog leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Scores
CVSS v3
6.5
EPSS
0.0034
EPSS Percentile
56.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Classification
CWE
CWE-284
CWE-266
Status
published
Affected Products (1)
totolink/a720r_firmware
Timeline
Published
May 05, 2025
Tracked Since
Feb 18, 2026