CVE-2025-2095

A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:ex1800t_firmware:9.1.0cu.2112_b20220316:*:*:*:*:*:*:*
cpe:2.3:h:totolink:ex1800t:-:*:*:*:*:*:*:*

History

03 Apr 2025, 15:29

Type Values Removed Values Added
CPE cpe:2.3:o:totolink:ex1800t_firmware:9.1.0cu.2112_b20220316:*:*:*:*:*:*:*
cpe:2.3:h:totolink:ex1800t:-:*:*:*:*:*:*:*
CWE CWE-78
References () https://github.com/kn0sky/cve/blob/main/TOTOLINK%20EX1800T/OS%20Command%20Injection%2003%20setDmzCfg-_ip.md - () https://github.com/kn0sky/cve/blob/main/TOTOLINK%20EX1800T/OS%20Command%20Injection%2003%20setDmzCfg-_ip.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.298953 - () https://vuldb.com/?ctiid.298953 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.298953 - () https://vuldb.com/?id.298953 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.515321 - () https://vuldb.com/?submit.515321 - Third Party Advisory, VDB Entry
References () https://www.totolink.net/ - () https://www.totolink.net/ - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Totolink ex1800t Firmware
Totolink ex1800t
Totolink

07 Mar 2025, 23:15

Type Values Removed Values Added
CWE CWE-77
CWE-78
CVSS v2 : unknown
v3 : 6.3
v2 : unknown
v3 : unknown

07 Mar 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-07 22:15

Updated : 2025-04-03 15:29


NVD link : CVE-2025-2095

Mitre link : CVE-2025-2095


JSON object : View

Products Affected

totolink

  • ex1800t
  • ex1800t_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')