CVE-2025-60702 carries a CVSS 3.1 base score of 6.5 against TOTOLINK A950RG router firmware version V5.9c.4592_B20191022_ALL. NVD classifies it as CWE-77 (Command Injection). VulnCheck’s KEV feed reports the CVE as exploited, dated September 1, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2025-60702 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description states the flaw lives in the system.so binary of the router’s firmware. The setDiagnosisCfg function retrieves a request parameter representing an IP domain value via websGetVar and concatenates it directly into a ping system command executed through CsteSystem(), with no sanitization of the input. An unauthenticated remote attacker can reach this code path through a specially crafted HTTP request to the router’s web interface and cause arbitrary commands to run on the device.
Evidence and confidence
- Medium confidence — the CVSS 6.5 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N), the CWE-77 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by a published third-party firmware research writeup. The exploitation report traces to VulnCheck KEV alone. - High exploitation probability — FIRST’s EPSS model scores this CVE at 0.02538, an 84.2nd percentile score as of our ingestion.
No field is in conflict between our two sources. Our source data does not carry a fixed-version field.
Why this matters
Passing an unsanitized, attacker-controlled value straight into a shell command executed via a diagnostic function is one of the oldest and most reliable command-injection patterns in embedded firmware — diagnostic tools like ping/traceroute wrappers are a recurring source of exactly this bug because they exist specifically to hand a user-supplied address to a system utility. The lack of any authentication requirement means exposure to this flaw is a direct function of whether the router’s web management interface is reachable; owners of TOTOLINK A950RG routers running the affected firmware should check for an update and, in the interim, keep the management interface off the public internet.
Frequently Asked Questions
What is CVE-2025-60702? A CVSS 6.5 command injection vulnerability (CWE-77) in TOTOLINK A950RG router firmware V5.9c.4592_B20191022_ALL, allowing an unauthenticated attacker to execute arbitrary commands via the router’s diagnostic configuration handler.
Is CVE-2025-60702 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 1, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by an unauthenticated remote attacker.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Our source data does not carry a fixed-version field. Consult TOTOLINK’s own site for firmware update availability for the A950RG model.
Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2025-60702. Exploitation status and the September 1, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.