Skip to main content
QUIETLYTIC
Vulnerability

TOTOLINK LR1200GB Vulnerability (CVE-2025-60687)

CVE-2025-60687 is a CVSS 6.5 unauthenticated command injection in TOTOLINK LR1200GB router firmware, per VulnCheck alone.

CVE-2025-60687
Threat Level
MEDIUM
CVSS
6.5
Status
Active Exploitation
Confidence
Medium
Affected Products
TOTOLINK LR1200GB (firmware V9.1.0u.6619_B20230130)

CVE-2025-60687 carries a CVSS 3.1 base score of 6.5 against TOTOLINK LR1200GB router firmware version V9.1.0u.6619_B20230130. NVD classifies it as CWE-77 (Command Injection). VulnCheck’s KEV feed reports the CVE as exploited, dated September 7, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2025-60687 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description, based on reverse-engineering research into the firmware’s cstecgi.cgi binary, states the binary reads a web request parameter representing a device IMEI number and validates it only by checking that it is 15 characters long, with no further content sanitization. NVD states that value is then inserted directly into a system command string and executed, meaning a maliciously crafted value for that parameter can execute arbitrary commands on the router without authentication.

Evidence and confidence

  • Medium confidence — the CVSS 6.5 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N), the CWE-77 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by a published third-party firmware research writeup. The exploitation report traces to VulnCheck KEV alone.
  • Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.06606, a 93.5th percentile score as of our ingestion — among the highest we’ve seen in a VulnCheck-only listing this cycle.

No field is in conflict between our two sources. Our source data does not carry a fixed-version field.

Why this matters

The vulnerable check here — validating only a parameter’s length rather than its content — is a common but insufficient input-validation pattern in embedded firmware, where a value that’s the “right shape” is treated as safe without checking what characters it actually contains. The near-94th-percentile EPSS score for an unauthenticated router command injection suggests active exploitation interest; owners of TOTOLINK LR1200GB routers running the affected firmware should check for a firmware update and, in the interim, ensure the router’s management interface is not exposed to the public internet.

Frequently Asked Questions

What is CVE-2025-60687? A CVSS 6.5 command injection vulnerability (CWE-77) in TOTOLINK LR1200GB router firmware V9.1.0u.6619_B20230130, allowing an unauthenticated attacker to execute arbitrary commands via a crafted IMEI-format request parameter that passes a length-only validation check.

Is CVE-2025-60687 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 7, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by an unauthenticated attacker.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Our source data does not carry a fixed-version field. Consult TOTOLINK’s own site for firmware update availability for the LR1200GB model.


Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2025-60687. Exploitation status and the September 7, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools