CVE-2025-2094: TOTOLINK EX1800T cstecgi.cgi setWiFiExtenderConfig os command injection
A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112B20220316. It has been rated as critical. Affected by this issue is the function setWiFiExtenderConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument apcliKey/key leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2094?
CVE-2025-2094 has been rated as critical due to its potential for os command injection.
How do I fix CVE-2025-2094?
To fix CVE-2025-2094, you should update to the latest firmware version provided by TOTOLINK that addresses this vulnerability.
What product is affected by CVE-2025-2094?
CVE-2025-2094 affects the TOTOLINK EX1800T router.
What type of vulnerability is CVE-2025-2094?
CVE-2025-2094 is an os command injection vulnerability.
How can CVE-2025-2094 be exploited?
An attacker can exploit CVE-2025-2094 by manipulating the apcliKey/key argument in the setWiFiExtenderConfig function.