CVE-2025-70327: Critical severity TOTOLINK X5000R vulnerability
TOTOLINK X5000R v9.1.0cu2415B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping command through CsteSystem without validating if the input starts with a hyphen (-). This allows remote authenticated attackers to inject arbitrary command-line options into the ping utility, potentially leading to a Denial of Service (DoS) by causing excessive resource consumption or prolonged execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70327?
CVE-2025-70327 is classified as a high severity vulnerability due to the potential for argument injection leading to command execution.
How do I fix CVE-2025-70327?
To mitigate CVE-2025-70327, update TOTOLINK X5000R to the latest firmware version that addresses this vulnerability.
What type of vulnerability is CVE-2025-70327?
CVE-2025-70327 is an argument injection vulnerability located in the setDiagnosisCfg handler of the TOTOLINK X5000R firmware.
Which products are affected by CVE-2025-70327?
CVE-2025-70327 affects the TOTOLINK X5000R running firmware version 9.1.0cu_2415_B20250515.
How can an attacker exploit CVE-2025-70327?
An attacker can exploit CVE-2025-70327 by sending specially crafted input to the setDiagnosisCfg handler, allowing them to execute arbitrary commands.