CVE-2025-60687: Command Injection

Published Nov 13, 2025
·
Updated

An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619B20230130 within the cstecgi.cgi binary (sub41EC68 function). The binary reads the "imei" parameter from a web request and verifies only that it is 15 characters long. The parameter is then directly inserted into a system command using sprintf() and executed with system(). Maliciously crafted IMEI input can execute arbitrary commands on the router without authentication.

Affected Software

3 affected components
TOTOLINK LR1200GB Router
All of the following
TOTOLINK Lr1200gb Firmware=9.1.0u.6619_b20230130
TOTOLINK LR1200GB

Event History

Nov 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-60687?

CVE-2025-60687 is considered a high severity vulnerability due to its potential for command injection.

2

How do I fix CVE-2025-60687?

To fix CVE-2025-60687, update the ToToLink LR1200GB Router firmware to the latest version provided by the vendor.

3

What systems are affected by CVE-2025-60687?

CVE-2025-60687 specifically affects the ToToLink LR1200GB Router with firmware version V9.1.0u.6619_B20230130.

4

What type of vulnerability is CVE-2025-60687?

CVE-2025-60687 is classified as an unauthenticated command injection vulnerability.

5

Can CVE-2025-60687 be exploited remotely?

Yes, CVE-2025-60687 can be exploited remotely due to the vulnerability's presence in a web-accessible interface.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203