CVE-2025-4270
MEDIUM EXPLOITEDTOTOLINK A720R 4.1.5cu.374 - Info Disclosure
Title source: llmDescription
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Config Handler. The manipulation of the argument topicurl with the input getInitCfg/getSysStatusCfg leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Scores
CVSS v3
5.3
EPSS
0.0040
EPSS Percentile
60.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitation Intel
VulnCheck KEV
2025-07-30
Classification
CWE
CWE-284
CWE-200
Status
published
Affected Products (1)
totolink/a720r_firmware
Timeline
Published
May 05, 2025
Tracked Since
Feb 18, 2026