Executive brief
A security misconfiguration has been identified in several TOTOLink router models, which are devices used to provide internet connectivity and local networking. The built-in file transfer service (FTP) is configured in a way that could allow an attacker to bypass security restrictions and access sensitive system files. This could lead to full control over the device, theft of data, or the ability to use the router as a jumping-off point to attack other devices on your private network.
Technical details
This vulnerability stems from an incorrect privilege assignment (CWE-266) within the vsftpd configuration of multiple TOTOLink router models. Specifically, the 'chroot_local_user' option is enabled in vsftpd.conf without accompanying security measures, which in certain vsftpd versions can be exploited to escape the restricted directory (chroot jail) if the user has write permissions on their root directory. An unauthenticated or low-privileged attacker could leverage this misconfiguration over the network to gain unauthorized access to the underlying filesystem. This can result in privilege escalation, sensitive data disclosure, or the ability to use the compromised router as a pivot for lateral movement within the internal network. No official patch is currently detailed in the advisory, though disabling the FTP service or manually hardening the vsftpd configuration are standard mitigations.
Affected products
- TOTOLink A7100RU Firmware 7.4
- TOTOLink A950RG Firmware 5.9
- TOTOLink T10 Firmware 5.9
Timeline
- 2025-07-21: disclosed
- 2025-07-21: advisory