CVE-2026-91853
TOTOLINK X5000R Export Ovpn cstecgi.cgi exportOvpn os command injection
CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler. The manipulation of the argument filetype leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
| CWE | CWE-78 CWE-77 |
| Vendor | totolink |
| Product | x5000r |
| Published | Sep 15, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for totolink x5000r
Be the first to know when new high vulnerabilities affecting totolink x5000r are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
TOTOLINK / X5000R
9.1.0cu.2089_B20211224
References
Credits
๐ awigwu76 (VulDB User)