Executive brief
A security vulnerability exists in the ToToLink LR1200GB router, a device used to provide wireless internet connectivity. An attacker can send a specially crafted web request to the router to take control of the device without needing a password. This could allow an unauthorized user to disrupt internet service or potentially access internal network traffic.
Technical details
An unauthenticated command injection vulnerability exists in the cstecgi.cgi binary (specifically the sub_41EC68 function) of the ToToLink LR1200GB router firmware V9.1.0u.6619_B20230130. The application retrieves the 'imei' parameter via websGetVar and performs a length check to ensure it is exactly 15 characters, but fails to sanitize the input for shell metacharacters. The unsanitized input is then passed to sprintf() to construct a system command ('cli_atc at+EGMR=1,7...') which is executed via system(). An attacker can exploit this by providing a 15-character string containing command separators (e.g., semicolons) to achieve remote code execution.
Affected products
- ToToLink LR1200GB Router V9.1.0u.6619_B20230130
Timeline
- 2025-11-13: advisory: NVD published date