Executive brief
A security vulnerability exists in the ToToLink A720R router, a device used to provide wireless internet connectivity. An attacker who can modify a specific system configuration file can take full control of the device by executing unauthorized commands. This could lead to the interception of network traffic, unauthorized access to connected devices, or a complete disruption of internet service.
Technical details
A command injection vulnerability exists in the 'sysconf' binary of ToToLink A720R firmware version V4.1.5cu.614_B20230630. The flaw is located in the sub_40BFA4 function, which reads network interface reinitialization data from the file '/var/system/linux_vlan_reinit'. The application performs insufficient validation by only checking if the input starts with 'eth' or 'wlan' before passing the string to the system() function via sub_40AC08. An attacker who can write to this file can use shell metacharacters (e.g., semicolons) to bypass the prefix check and execute arbitrary system commands. While the vulnerability requires the ability to write to a local file, the CVSS vector provided by CISA-ADP suggests potential network-based vectors for exploitation.
Affected products
- ToToLink A720R V4.1.5cu.614_B20230630
Timeline
- 2025-11-13: advisory: Initial disclosure and NVD publication