CVE-2025-14586: TOTOLINK X5000R cstecgi.cgi snprintf os command injection
A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14586?
The severity of CVE-2025-14586 has not been explicitly rated, but it involves remote command injection which typically indicates a high risk.
How do I fix CVE-2025-14586?
To fix CVE-2025-14586, apply the latest firmware updates from TOTOLINK that address the vulnerability.
What systems are affected by CVE-2025-14586?
CVE-2025-14586 affects the TOTOLINK X5000R running version 9.1.0cu.2089_B20211224.
What type of vulnerability is CVE-2025-14586?
CVE-2025-14586 is classified as an OS command injection vulnerability.
Can CVE-2025-14586 be exploited remotely?
Yes, CVE-2025-14586 can be exploited remotely due to its nature of command injection.