Description
A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2025-12-12: | Advisory disclosed |
| 2025-12-12: | VulDB entry created |
| 2025-12-14: | VulDB entry last update |
Credits
awigwu76 (VulDB User)
awigwu76 (VulDB User)
References
vuldb.com/?id.336206 (VDB-336206 | TOTOLINK X5000R cstecgi.cgi snprintf os command injection)
vuldb.com/?ctiid.336206 (VDB-336206 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.705593 (Submit #705593 | TOTOLINK X5000R v9.1.0cu.2089_B20211224 RCE)
github.com/awigwu76/TOTOLINK_X5000R/blob/main/1.md
www.totolink.net/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.