Impact
A vulnerability in TOTOLINK X5000R firmware 9.1.0cu.2089_B20211224 allows an attacker to trigger an OS command injection through the exportOvpn function in the Export Ovpn Handler. By manipulating the filetype parameter, which is passed unsafely to the operating system, an attacker can execute arbitrary commands on the router, potentially gaining local privileges or compromising the device entirely.
Affected Systems
Devices running the TOTOLINK X5000R router with firmware 9.1.0cu.2089_B20211224 are affected. The vulnerability is specific to the Export cstecgi.cgi?action=exportOvpn&type=user endpoint. No other TOTOLINK products or firmware versions are reported to be impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of 0.01369 indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the injection occurs through a web interface, an attacker only needs remote network access to the device’s management interface, making the attack relatively easy to launch. If successful, the attacker could alter configuration, exfiltrate data, or gain full control of the device.
OpenCVE Enrichment