CVE-2025-60683: n/a
A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the sub_40BFA4 function that handles network interface reinitialization from '/var/system/linux_vlan_reinit'. Input is only partially validated by checking the prefix of interface names, and is concatenated into shell commands executed via system() without escaping. An attacker with write access to this file can execute arbitrary commands on the device.
AI Analysis
Technical Summary
CVE-2025-60683 describes a command injection vulnerability in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630. The vulnerability resides in the sysconf binary, specifically in the sub_40BFA4 function that processes network interface reinitialization commands from the '/var/system/linux_vlan_reinit' file. The function only partially validates interface name prefixes and concatenates input into shell commands executed via system() without proper escaping. This allows an attacker with write access to the file to inject and execute arbitrary commands on the router.
Potential Impact
An attacker who can write to the '/var/system/linux_vlan_reinit' file can execute arbitrary commands on the router with the privileges of the sysconf binary. This can lead to partial confidentiality and integrity loss on the device, but does not affect availability. The CVSS 3.1 base score is 6.5 (medium severity) with network attack vector, low attack complexity, no privileges required, no user interaction, and impacts on confidentiality and integrity.
Mitigation Recommendations
No patch or official fix is currently available for this vulnerability. Since the vulnerability requires write access to a specific system file, restricting write permissions to '/var/system/linux_vlan_reinit' and limiting access to trusted users can mitigate exploitation risk. Monitor vendor advisories for updates or patches addressing this issue.
CVE-2025-60683: n/a
Description
A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the sub_40BFA4 function that handles network interface reinitialization from '/var/system/linux_vlan_reinit'. Input is only partially validated by checking the prefix of interface names, and is concatenated into shell commands executed via system() without escaping. An attacker with write access to this file can execute arbitrary commands on the device.
CVSS v3.1
Score 6.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-60683 describes a command injection vulnerability in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630. The vulnerability resides in the sysconf binary, specifically in the sub_40BFA4 function that processes network interface reinitialization commands from the '/var/system/linux_vlan_reinit' file. The function only partially validates interface name prefixes and concatenates input into shell commands executed via system() without proper escaping. This allows an attacker with write access to the file to inject and execute arbitrary commands on the router.
Potential Impact
An attacker who can write to the '/var/system/linux_vlan_reinit' file can execute arbitrary commands on the router with the privileges of the sysconf binary. This can lead to partial confidentiality and integrity loss on the device, but does not affect availability. The CVSS 3.1 base score is 6.5 (medium severity) with network attack vector, low attack complexity, no privileges required, no user interaction, and impacts on confidentiality and integrity.
Mitigation Recommendations
No patch or official fix is currently available for this vulnerability. Since the vulnerability requires write access to a specific system file, restricting write permissions to '/var/system/linux_vlan_reinit' and limiting access to trusted users can mitigate exploitation risk. Monitor vendor advisories for updates or patches addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2025-09-26T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 6915fe5477eaf5a84960394c
Added to database: 11/13/2025, 15:50:44 UTC
Last enriched: 07/05/2026, 21:33:14 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 116
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.