CVE-2026-15204: Totolink x5000r

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerability is the function exportOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manipulation results in path traversal. The attack may be launched remotely.

Affected products

  • Totolink x5000r: version 9.1.0cu.2350_B20230313 only; version 9.1.0cu.2415_B20250515 only

Published 2026-07-09. Last modified 2026-07-14.