CVE-2025-4269: TOTOLINK A720R Log cstecgi.cgi access control
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi of the component Log Handler. The manipulation of the argument topicurl with the input clearDiagnosisLog/clearSyslog/clearTracerouteLog leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4269?
CVE-2025-4269 is classified as a critical severity vulnerability.
How do I fix CVE-2025-4269?
To fix CVE-2025-4269, update the firmware of your TOTOLINK A720R to the latest version provided by the vendor.
What component is affected by CVE-2025-4269?
CVE-2025-4269 affects the Log Handler component of the TOTOLINK A720R.
What type of vulnerability is CVE-2025-4269?
CVE-2025-4269 is a manipulation vulnerability related to the processing of certain input arguments.
Which products are impacted by CVE-2025-4269?
CVE-2025-4269 impacts the TOTOLINK A720R device running firmware version 4.1.5cu.374.