Home

Description

In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

PUBLISHED Reserved 2025-04-22 | Published 2025-07-21 | Updated 2025-07-22 | Assigner mitre

References

totolink.com

gist.github.com/TPCchecker/d7306649f51ca25e22dd6532546a58f3

cve.org (CVE-2025-44655)

nvd.nist.gov (CVE-2025-44655)

Download JSON