CVE-2025-14586 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?actio…
Medium CVSS: 5.3

CVE-2025-14586

A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Vendor
Totolink
Product
X5000r Firmware
CWE
CWE-77
Yayın Tarihi
2025-12-13 16:16:51
Güncelleme
2025-12-18 02:33:01
Source Identifier
cna@vuldb.com
KEV Date Added
-

Kategoriler

Referanslar