CVE-2025-2095

A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:ex1800t_firmware:9.1.0cu.2112_b20220316:*:*:*:*:*:*:*
cpe:2.3:h:totolink:ex1800t:-:*:*:*:*:*:*:*

History

03 Apr 2025, 15:29

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:o:totolink:ex1800t_firmware:9.1.0cu.2112_b20220316:*:*:*:*:*:*:*
cpe:2.3:h:totolink:ex1800t:-:*:*:*:*:*:*:*
First Time Totolink ex1800t Firmware
Totolink ex1800t
Totolink
CWE CWE-78
References () https://github.com/kn0sky/cve/blob/main/TOTOLINK%20EX1800T/OS%20Command%20Injection%2003%20setDmzCfg-_ip.md - () https://github.com/kn0sky/cve/blob/main/TOTOLINK%20EX1800T/OS%20Command%20Injection%2003%20setDmzCfg-_ip.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.298953 - () https://vuldb.com/?ctiid.298953 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.298953 - () https://vuldb.com/?id.298953 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.515321 - () https://vuldb.com/?submit.515321 - Third Party Advisory, VDB Entry
References () https://www.totolink.net/ - () https://www.totolink.net/ - Product

07 Mar 2025, 23:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.3
v2 : unknown
v3 : unknown
CWE CWE-77
CWE-78

07 Mar 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-07 22:15

Updated : 2025-04-03 15:29


NVD link : CVE-2025-2095

Mitre link : CVE-2025-2095


JSON object : View

Products Affected

totolink

  • ex1800t
  • ex1800t_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')