CVE-2025-4270: TOTOLINK A720R Config cstecgi.cgi information disclosure
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Config Handler. The manipulation of the argument topicurl with the input getInitCfg/getSysStatusCfg leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4270?
CVE-2025-4270 has been classified as a problematic vulnerability.
How do I fix CVE-2025-4270?
To fix CVE-2025-4270, update the TOTOLINK A720R firmware to the latest version available.
What component is affected by CVE-2025-4270?
CVE-2025-4270 affects the Config Handler component of the TOTOLINK A720R device.
What is the attack vector for CVE-2025-4270?
CVE-2025-4270 can be exploited by manipulating the argument topicurl in the /cgi-bin/cstecgi.cgi file.
Which device is impacted by CVE-2025-4270?
CVE-2025-4270 impacts the TOTOLINK A720R router.