CVE-2025-60682: Command Injection
A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614B20230630 within the cloudupdatecheck binary, specifically in the sub402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell commands and executed via system() without any sanitization or escaping. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ToToLink A720R Router firmwareto a version that resolves this vulnerability.Fixed in V4.1.5cu.614_B20230630 - Compensating control
Block inbound network access to the router from untrusted/unauthenticated sources (e.g., restrict WAN/management access via firewall/ACL) to reduce exposure to the unauthenticated command injection.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60682?
CVE-2025-60682 is classified as a critical severity vulnerability due to its potential for command injection.
How do I fix CVE-2025-60682?
To mitigate CVE-2025-60682, update the ToToLink A720R Router firmware to the latest version provided by the vendor.
What components are affected by CVE-2025-60682?
CVE-2025-60682 affects the cloudupdate_check binary in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630.
What kind of vulnerability is CVE-2025-60682?
CVE-2025-60682 is a command injection vulnerability that allows attackers to execute arbitrary commands on the affected router.
Can CVE-2025-60682 be exploited remotely?
Yes, CVE-2025-60682 can be exploited remotely if an attacker can send crafted requests to the vulnerable router.