CVE-2026-11494: TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation
Published Jun 8, 2026
·Updated
A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least privilege violation. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
1 affected component
TOTOLINK TOTOLINK AC1200 T8=4.1.5cu.8611
Event History
Jun 8, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-11494?
CVE-2026-11494 has a medium severity score of 4.3.
2
What does CVE-2026-11494 involve?
CVE-2026-11494 involves a least privilege violation in the vsftpd component of the TOTOLINK AC1200 T8.
3
How can I mitigate the risk of CVE-2026-11494?
To mitigate CVE-2026-11494, ensure that appropriate permissions are set on the vsftpd configuration file.
4
Is CVE-2026-11494 exploitable remotely?
Yes, CVE-2026-11494 can be exploited remotely.
5
What impact does CVE-2026-11494 have on system integrity?
CVE-2026-11494 allows for integrity violations due to least privilege issues.