MEDIUM
TOTOLINK N200RE cstecgi.cgi sub_41A0F8 os command injection
Published Jul 8, 2025
5.3
MEDIUMCVSS 4.0
EPSS 2.41%
Description
A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the function sub_41A0F8 of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Hostname leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 9.3.5u.6095_B20200916StatusaffectedConstraints-
- Version 9.3.5u.6139_B20201216StatusaffectedConstraints-
- Version
Configuration 1
AND
- 9.3.5u.6095_b20200916
Configuration 2
AND
- 9.3.5u.6139_b20201216
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-20355 Advisory
- https://github.com/FLY200503/IoT-vul/blob/master/Totolink/N200RE/README.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.315092 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.315092 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.606230 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.totolink.net/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-20355 | Advisory | |
| https://github.com/FLY200503/IoT-vul/blob/master/Totolink/N200RE/README.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.315092 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.315092 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.606230 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.totolink.net/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jul 8, 2025
Updated Jul 8, 2025
Reserved Jul 7, 2025
Link CVE-2025-7154
CISA Vulnrichment
Updated Jul 8, 2025
ENISA EUVD
EUVD-2025-20355 Assigner VulDB
Published Jul 8, 2025
Updated Jul 8, 2025
Exploited since n/a
Link EUVD-2025-20355