CVE-2025-60702: Totolink a950rg Firmware
Medium severity, CVSS 6.5. EPSS: 2.5% chance of exploitation in the next 30 days.
A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagnosisCfg` function retrieves the `ipDoamin` parameter from user input via `websGetVar` and concatenates it directly into a `ping` system command executed via `CsteSystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.
Affected products
- Totolink a950rg Firmware: version 5.9c.4592_b20191022 only
Published 2025-11-13. Last modified 2026-06-17.