Impact
The vulnerability lies in the vsftpd configuration file of the TOTOLINK AC1200 T8 router, allowing an attacker to violate the system’s least privilege rule—a direct manifestation of CWE‑272, Least Privilege Violation, and also a permissions issue per CWE‑266. This can result in unauthorized elevation of privileges and potential modification of the device’s operating state.
Affected Systems
Devices from TOTOLINK branded as AC1200 T8, specifically those running firmware version 4.1.5cu.8611, are affected. No other product revisions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack may be initiated remotely and a publicly disclosed exploit exists, meaning attackers can achieve the privilege‑escalation flaw without local access.
OpenCVE Enrichment