TOTOLINK A720R Missing Authentication Vulnerability in Reboot Function

Vulnerability

A critical vulnerability in the TOTOLINK A720R router, specifically in the firmware version 4.1.5cu.374, allows for unauthorized device reboots. This issue arises in the '/cgi-bin/cstecgi.cgi' file, where the 'topicurl' parameter can be manipulated to initiate a reboot without authentication. The vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability allows for unauthorized reboots of the affected device.

Reproduction

To reproduce this vulnerability, send a POST request to '/cgi-bin/cstecgi.cgi' with the 'topicurl' parameter set to 'RebootSystem'. This can be done using a tool like curl or Postman, or through a simple script that sends HTTP POST requests. Ensure that the request includes the necessary headers, such as 'X-Requested-With' and 'User-Agent', to mimic a legitimate browser request.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm