VendorsTOTOLINKx5000r_firmware9.1.0cu.2415_b20250515
Vulnerabilities

TOTOLINK X5000r Firmware 9.1.0u.6118 B20201102 9.1.0cu.2415_b20250515

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-9934
TOTOLINK X5000R cstecgi.cgi sub_410C34 command injection
Published 2025-09-03 · Analyzed
9.8EPSS 0.037
CVE-2025-70327
TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping command through CsteSystem without validating if the input starts with a hyphen (-). This allows remote authenticated attackers to inject arbitrary command-line options into the ping utility, potentially leading to a Denial of Service (DoS) by causing excessive resource consumption or prolonged execution.
Published 2026-02-23 · Analyzed
9.8EPSS 0.007
CVE-2025-70329
TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without adequate validation or filtering. This allows an authenticated attacker to execute arbitrary shell commands with root privileges by injecting shell metacharacters into the affected parameters.
Published 2026-02-23 · Analyzed
8.0EPSS 0.033
CVE-2025-67445
TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (CONTENT_LENGTH + 1) without sufficient bounds checking. When lighttpd s request size limit is not enforced, a crafted large POST request can cause memory exhaustion or a segmentation fault, leading to a crash of the management CGI and loss of availability of the web interface.
Published 2026-02-24 · Modified
7.5EPSS 0.003