PT-2025-30293 · Totolink · Totolink A950Rg+2

Published

2025-07-21

·

Updated

2025-07-22

·

CVE-2025-44655

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLink A7100RU versions 7.4 TOTOLink A950RG versions 5.9 TOTOLink T10 versions 5.9
Description The chroot local user option is enabled in the vsftpd.conf file. This configuration could allow unauthorized access to system files, privilege escalation, or the use of a compromised server as a pivot point for internal network attacks.
Recommendations TOTOLink A7100RU version 7.4: Disable the chroot local user option in the vsftpd.conf file. TOTOLink A950RG version 5.9: Disable the chroot local user option in the vsftpd.conf file. TOTOLink T10 version 5.9: Disable the chroot local user option in the vsftpd.conf file.

Fix

LPE

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-44655

Affected Products

Totolink A7100Ru
Totolink A950Rg
Totolink T10