Executive brief
A security vulnerability has been identified in the TOTOLINK AC1200 T8 router, a device used to provide wireless internet connectivity. The flaw involves improper privilege settings within the device's file transfer service configuration. If exploited, a remote attacker with basic user access could perform actions beyond their intended permissions, potentially compromising the integrity of files stored on or managed by the device.
Technical details
A least privilege violation (CWE-272) and incorrect privilege assignment (CWE-266) exists in the TOTOLINK AC1200 T8 router running firmware version 4.1.5cu.8611. The vulnerability is located within the configuration file /etc/vsftpd.conf of the vsftpd component. A remote attacker with low-privileged credentials can exploit this misconfiguration to perform unauthorized modifications or bypass intended access restrictions. The exploit has been publicly disclosed, increasing the risk of exploitation. As of the advisory date, no specific patch has been confirmed, though users are advised to monitor the vendor's support page for firmware updates.
Affected products
- TOTOLINK AC1200 T8 4.1.5cu.8611
Timeline
- 2026-06-08: advisory: NVD publication date
- 2026-06-08: disclosed: Public disclosure of the exploit