CVE-2026-15204: TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal
Published Jul 9, 2026
·Updated
A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415B20250515/9.1.0cu.2350B20230313. Affected by this vulnerability is the function exportOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manipulation results in path traversal. The attack may be launched remotely.
Affected Software
2 affected components
TOTOLINK X5000R=9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313
OpenVPN Export cstecgi.cgi exportOvpn
Event History
Jul 9, 2026
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-15204?
CVE-2026-15204 has a severity rating of medium at 5.3.
2
How do I fix CVE-2026-15204?
To fix CVE-2026-15204, ensure you upgrade the TOTOLINK X5000R to the latest firmware version.
3
What component is affected by CVE-2026-15204?
CVE-2026-15204 affects the OpenVPN Export functionality found in the cstecgi.cgi file.
4
What type of attack can be launched due to CVE-2026-15204?
CVE-2026-15204 allows for a path traversal attack that can be executed remotely.
5
Which versions of TOTOLINK X5000R are affected by CVE-2026-15204?
TOTOLINK X5000R versions 9.1.0cu.2415_B20250515 and 9.1.0cu.2350_B20230313 are affected by CVE-2026-15204.