CVE-2026-11494 PUBLISHED

TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation

Assigner: VulDB
Reserved: 07.06.2026 Published: 08.06.2026 Updated: 08.06.2026

A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least privilege violation. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor TOTOLINK
Product AC1200 T8
Versions
  • Version 4.1.5cu.8611 is affected

Credits

  • L-14 (VulDB User) reporter

References

Problem Types

  • Least Privilege Violation CWE
  • Incorrect Privilege Assignment CWE