In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
2024-08-13T14:15:13.160
2025-04-04T14:35:31.433
Analyzed
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | x5000r_firmware | 9.1.0cu.2350_b20230313 | Yes |
Hardware | totolink | x5000r | - | No |