Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-7154


A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the function sub_41A0F8 of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Hostname leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.


Published

2025-07-08T01:15:26.200

Last Modified

2025-07-16T19:35:06.347

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-77
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System totolink n200re_firmware 9.3.5u.6095_b20200916 Yes
Hardware totolink n200re - No
Operating System totolink n200re_firmware 9.3.5u.6139_b20201216 Yes
Hardware totolink n200re - No

References