CVE-2025-9934: TOTOLINK X5000R cstecgi.cgi sub_410C34 command injection
A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415B20250515. This affects the function sub410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9934?
CVE-2025-9934 is classified as a critical vulnerability due to its potential for remote command injection.
How do I fix CVE-2025-9934?
To mitigate CVE-2025-9934, update the TOTOLINK X5000R firmware to the latest version provided by the vendor.
Who is affected by CVE-2025-9934?
CVE-2025-9934 affects users of the TOTOLINK X5000R running firmware version 9.1.0cu.2415_B20250515.
Can CVE-2025-9934 be exploited remotely?
Yes, CVE-2025-9934 allows for remote exploitation through command injection if the vulnerability is present.
What are the implications of CVE-2025-9934?
Exploitation of CVE-2025-9934 could lead to unauthorized access and control of the affected device.