CVE-2025-9934: Totolink x5000r Firmware
Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.
A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected products
- Totolink x5000r Firmware: version 9.1.0cu.2415_b20250515 only
Published 2025-09-04. Last modified 2026-06-17.