CVE-2025-2095: TOTOLINK EX1800T cstecgi.cgi setDmzCfg os command injection
A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112B20220316. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2095?
CVE-2025-2095 is classified as a critical vulnerability.
How do I fix CVE-2025-2095?
To fix CVE-2025-2095, update your TOTOLINK EX1800T device to the latest firmware version available from the manufacturer.
What type of vulnerability is CVE-2025-2095?
CVE-2025-2095 is an OS command injection vulnerability affecting the setDmzCfg function in the TOTOLINK EX1800T.
Can CVE-2025-2095 be exploited remotely?
Yes, CVE-2025-2095 can be exploited remotely.
Which file is associated with CVE-2025-2095?
CVE-2025-2095 is associated with the file /cgi-bin/cstecgi.cgi in the TOTOLINK EX1800T.