Three Bugs in One Binary: A Vulnerability Research Walkthrough on the TOTOLINK A720R (CVE-2025-63821, CVE-2026-82539)
Description I bought a TOTOLINK A720R specifically for this. TOTOLINK was a vendor I had never done any research on, so I picked up one of their models to take a look. It looked like an easy target: a small SOHO router with a web-based admin panel and the usual embedded stack. What started as a quick look at the web interface turned into three separate findings, all reachable through the same binary, cstecgi.cgi, which handles almost the entire web UI. ...