CVE-2025-60686 describes a local stack-based buffer overflow in the infostat.cgi and cstecgi.cgi binaries of specific ToToLink router models (A720R, LR1200GB, NR1800X). The vulnerability arises from improper handling of data parsed from /proc/net/arp, where sscanf() with "%s" format specifiers writes into fixed-size stack buffers without length validation. This allows an attacker who can control /proc/net/arp to trigger memory corruption. Rated Medium (CVSS 5.1), the attack requires local access (AV:L) and can lead to denial of service or potentially arbitrary code execution (A:L, C:L). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.5cu.614_b20230630CPE matchmatch criteria | cpe:2.3:o:totolink:a720r_firmware:4.1.5cu.614_b20230630:*:*:*:*:*:*:* | ||
9.1.0u.6619_b20230130CPE matchmatch criteria | cpe:2.3:o:totolink:lr1200gb_firmware:9.1.0u.6619_b20230130:*:*:*:*:*:*:* | ||
9.1.0u.6681_b20230703CPE matchmatch criteria | cpe:2.3:o:totolink:nr1800x_firmware:9.1.0u.6681_b20230703:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.