CVE-2025-2096: TOTOLINK EX1800T cstecgi.cgi setRebootScheCfg os command injection
A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112B20220316. This vulnerability affects the function setRebootScheCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mode/week/minute/recHour leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2096?
CVE-2025-2096 is classified as a critical vulnerability.
What type of vulnerability is CVE-2025-2096?
CVE-2025-2096 is an OS command injection vulnerability.
How do I fix CVE-2025-2096?
To fix CVE-2025-2096, update the TOTOLINK EX1800T firmware to the latest version provided by TOTOLINK.
What is affected by CVE-2025-2096?
CVE-2025-2096 affects the TOTOLINK EX1800T version 9.1.0cu.2112_B20220316.
What is the impact of CVE-2025-2096?
Exploitation of CVE-2025-2096 can allow an attacker to execute arbitrary OS commands on the affected device.