Impact
A path traversal vulnerability exists in the exportOvpn function of the /web/cgi-bin/cstecgi.cgi file within the OpenVPN Export component of TOTOLINK X5000R firmware. The flaw allows an attacker to craft a request that resolves a file path outside the intended directory, enabling the reading of arbitrary files on the device. By exposing sensitive configuration data or credentials, the vulnerability threatens the confidentiality of network settings.
Affected Systems
Affected are TOTOLINK X5000R model firmware versions 9.1.0cu.2415_B20250515 and 9.1.0cu.2350_B20230313. The flaw resides in the OpenVPN Export CGI interface exposed by those firmware releases.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of <1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploits yet. Attackers can target the /web/cgi-bin/cstecgi.cgi endpoint from outside the local network, sending specially crafted requests that trigger the traversal and leak file contents. Based on the description, it is inferred that no authentication is required to reach the CGI, so the path traversal can be exploited remotely without credentials.
OpenCVE Enrichment