Medium severity5.3NVD Advisory· Published Jun 9, 2026
CVE-2026-11620
CVE-2026-11620
Description
A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation results in least privilege violation. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
1- Totolink Routers: Three vsftpd Least Privilege Vulnerabilities DisclosedVypr Intelligence · Jun 9, 2026