Description
A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerability is the function exportOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manipulation results in path traversal. The attack may be launched remotely.
Published: 2026-07-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal vulnerability exists in the exportOvpn function of the /web/cgi-bin/cstecgi.cgi file within the OpenVPN Export component of TOTOLINK X5000R firmware. The flaw allows an attacker to craft a request that resolves a file path outside the intended directory, enabling the reading of arbitrary files on the device. By exposing sensitive configuration data or credentials, the vulnerability threatens the confidentiality of network settings.

Affected Systems

Affected are TOTOLINK X5000R model firmware versions 9.1.0cu.2415_B20250515 and 9.1.0cu.2350_B20230313. The flaw resides in the OpenVPN Export CGI interface exposed by those firmware releases.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score of <1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploits yet. Attackers can target the /web/cgi-bin/cstecgi.cgi endpoint from outside the local network, sending specially crafted requests that trigger the traversal and leak file contents. Based on the description, it is inferred that no authentication is required to reach the CGI, so the path traversal can be exploited remotely without credentials.

Generated by OpenCVE AI on July 28, 2026 at 08:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to a firmware version that includes the fix for the path traversal in the OpenVPN Export CGI.
  • If an update is not immediately available, disable the OpenVPN Export feature through the device settings or block access to /web/cgi-bin/cstecgi.cgi using ACLs or firewall rules.
  • Implement strict input validation or restrict allowed file paths for the exportOvpn function to prevent traversal, ensuring only legitimate configuration files are processed.

Generated by OpenCVE AI on July 28, 2026 at 08:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink x5000r
Vendors & Products Totolink x5000r

Thu, 09 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerability is the function exportOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manipulation results in path traversal. The attack may be launched remotely.
Title TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal
First Time appeared Totolink
Totolink x5000r Firmware
Weaknesses CWE-22
CPEs cpe:2.3:o:totolink:x5000r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink x5000r Firmware
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:N/AC:M/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink X5000r X5000r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-14T01:07:22.744Z

Reserved: 2026-07-09T06:54:25.124Z

Link: CVE-2026-15204

cve-icon Vulnrichment

Updated: 2026-07-14T01:07:18.315Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')