CVE-2025-14586Medium· 6.3▾ SunlitA vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os comm…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.8%
A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
x5000r_firmware = 9.1.0cu.2089_b20211224Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100896Critical· 9.9A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030
CVE-2026-91853High· 7.4A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224
CVE-2026-93742Critical· 9.9A weakness has been identified in Totolink A3002MU Hh-B20211125.1046
CVE-2025-59834Critical· 9.8ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB
CVE-2025-15472High· 7.2A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0
CVE-2025-9580Medium· 6.3A security vulnerability has been detected in LB-LINK BL-X26 1.2.8