Impact
A vulnerability in TOTOLINK X5000R firmware 9.1.0cu.2089_B20211224 allows an attacker to trigger an OS command injection through the exportOvpn function in the Export Ovpn Handler. By manipulating the filetype parameter, which is passed unsafely to the operating system, an attacker can execute arbitrary commands on the router. The flaw enables the attacker to gain local privileges or potentially compromise the device entirely.
Affected Systems
Devices running the TOTOLINK X5000R router with firmware 9.1.0cu.2089_B20211224 are affected. The vulnerability is specific to the Export Ovpn Handler (/cgi-bin/cstecgi.cgi?action=exportOvpn&type=user). No other TOTOLINK products or firmware versions are reported to be impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The exploit is remote and publicly disclosed, but no EPSS data is available and it is not listed in the CISA KEV catalog. Because the injection occurs via a web interface, an attacker only needs remote network access to the device’s management interface, making the attack relatively easy to launch. If successful, the attacker could alter configuration, exfiltrate data, or gain full control of the device.
OpenCVE Enrichment