In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
2024-08-13T14:15:14.203
2025-04-04T14:35:41.613
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | totolink | x5000r_firmware | 9.1.0cu.2350_b20230313 | Yes |
| Hardware | totolink | x5000r | - | No |