Executive brief
A security vulnerability exists in the TOTOLINK CP450 wireless router. The device's file transfer service (FTP) is configured with incorrect permissions, which could allow a logged-in user to perform actions they should not be authorized to do. This could lead to unauthorized modification of files or settings on the device, potentially compromising its integrity.
Technical details
A vulnerability classified as Incorrect Privilege Assignment (CWE-266) and Least Privilege Violation (CWE-272) exists in TOTOLINK CP450 version 4.1.0cu.747. The issue resides in the configuration of the vsftpd component, specifically within the /etc/vsftpd.conf file. A remote attacker with low-privileged credentials can exploit this misconfiguration to perform unauthorized file system operations. The exploit has been publicly disclosed, increasing the risk of utilization. No official patch has been confirmed in the provided advisory.
Affected products
- TOTOLINK CP450 4.1.0cu.747
Timeline
- 2026-06-08: disclosed: Public disclosure of the vulnerability and exploit details.
- 2026-06-08: advisory: NVD and VulDB published the vulnerability record.