github.comrelated
https://github.com/at0de/my_vulns/blob/main/TOTOLINK/A720R/getInitCfg.md CVE-2025-4270
MEDIUM
TOTOLINK A720R Config cstecgi.cgi information disclosure
Record summary
CVE-2025-4270 has a selected CVSS score of 6.9 (medium).
Description
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Config Handler. The manipulation of the argument topicurl with the input getInitCfg/getSysStatusCfg leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 30, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 5, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 4.1.5cu.374 | affected | |
a720r_firmwareBrowse totolink / a720r_firmware | VulnCheck | Version data not supplied | |
References
7github.comexploit
https://github.com/at0de/my_vulns/blob/main/TOTOLINK/A720R/getSysStatusCfg.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-4270 VDB-307374 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.307374 VDB-307374 | TOTOLINK A720R Config cstecgi.cgi information disclosurevdb entryTechnical description
https://vuldb.com/?id.307374 Submit #563442 | TOTOLINK A720R V4.1.5cu.374 Exposure of Sensitive System Information to an Unauthorized ContThird-party advisory
https://vuldb.com/?submit.563442 totolink.netproduct
https://www.totolink.net/