CVE-2025-9934: Totolink x5000r Firmware

Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.

A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

Affected products

  • Totolink x5000r Firmware: version 9.1.0cu.2415_b20250515 only

Published 2025-09-04. Last modified 2026-06-17.