Medium severity4.3NVD Advisory· Published Jun 8, 2026· Updated Jun 9, 2026
CVE-2026-11554
CVE-2026-11554
Description
A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected products
1Patches
Vulnerability mechanics
References
6News mentions
1- Totolink Routers: Three vsftpd Least Privilege Vulnerabilities DisclosedVypr Intelligence · Jun 9, 2026