CVE-2025-14586 | TOTOLINK X5000R 9.1.0cu.2089_B20211224 cstecgi.cgi?action=exportOvpn&type=user snprintf User os command injection
A vulnerability identified as critical has been detected in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os command injection.
This vulnerability is registered as CVE-2025-14586. Remote exploitation of the attack is possible. Furthermore, an exploit is available.