Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 2 min 121 bronnen 2 kritiek 14 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2025-14586

MEDIUM · 6.3 CVSS Gepubliceerd: CWE-77

Beschrijving

A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

Vendors

Totolink

Affected products

X5000r Firmware X5000r

References