TOTOLINK A3700R Improper Access Control Vulnerability in L2TP Server Configuration

Vulnerability

A critical vulnerability exists in the TOTOLINK A3700R router, specifically in version 9.1.2u.5822_B20200513. The issue arises in the 'setL2tpServerCfg' function within the '/cgi-bin/cstecgi.cgi' file, where improper access controls allow for remote manipulation. This vulnerability has been publicly disclosed and could be exploited by attackers.

Impact

Exploitation of this vulnerability could lead to unauthorized access or manipulation of the L2TP server configuration on the affected router.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.0
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.