A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the function sub_41A0F8 of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Hostname leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
2025-07-08T01:15:26.200
2025-07-16T19:35:06.347
Analyzed
CVSSv3.1: 6.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | n200re_firmware | 9.3.5u.6095_b20200916 | Yes |
Hardware | totolink | n200re | - | No |
Operating System | totolink | n200re_firmware | 9.3.5u.6139_b20201216 | Yes |
Hardware | totolink | n200re | - | No |