Description
A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-06-08: | Advisory disclosed |
| 2026-06-08: | VulDB entry created |
| 2026-06-08: | VulDB entry last update |
Credits
L-14 (VulDB User)
References
vuldb.com/vuln/369164 (VDB-369164 | TOTOLINK CP450 vsftpd vsftpd.conf least privilege violation)
vuldb.com/vuln/369164/cti (VDB-369164 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-11554 (CVE-2026-11554 | CVE Analysis and Report)
vuldb.com/submit/834821 (Submit #834821 | TOTOLink CP450 V4.1.0cu.747 Misconfiguration)
www.notion.so/...ba989080c3b39ac3984d2ff44d?source=copy_link
www.totolink.net/