<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>#CVE-2025-63821 on Nico's Security Research</title><link>https://nico-security.com/tags/%23cve-2025-63821/</link><description>Recent content in #CVE-2025-63821 on Nico's Security Research</description><generator>Hugo -- 0.166.0</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://nico-security.com/tags/%23cve-2025-63821/index.xml" rel="self" type="application/rss+xml"/><item><title>Three Bugs in One Binary: A Vulnerability Research Walkthrough on the TOTOLINK A720R (CVE-2025-63821, CVE-2026-82539)</title><link>https://nico-security.com/posts/totolink-a720r/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://nico-security.com/posts/totolink-a720r/</guid><description>&lt;h2 id="description"&gt;Description&lt;/h2&gt;
&lt;p&gt;I bought a TOTOLINK A720R specifically for this. TOTOLINK was a vendor I had never done any research on, so I picked up one of their models to take a look. It looked like an easy target: a small SOHO router with a web-based admin panel and the usual embedded stack. What started as a quick look at the web interface turned into three separate findings, all reachable through the same binary, &lt;code&gt;cstecgi.cgi&lt;/code&gt;, which handles almost the entire web UI.&lt;/p&gt;</description></item></channel></rss>