Vulnerability Description
A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | Ex1800T Firmware | 9.1.0cu.2112_b20220316 |
| Totolink | Ex1800T | - |
Related Weaknesses (CWE)
References
- https://github.com/kn0sky/cve/blob/main/TOTOLINK%20EX1800T/OS%20Command%20InjectExploitThird Party Advisory
- https://vuldb.com/?ctiid.298953Permissions RequiredVDB Entry
- https://vuldb.com/?id.298953Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.515321Third Party AdvisoryVDB Entry
- https://www.totolink.net/Product
- https://github.com/kn0sky/cve/blob/main/TOTOLINK%20EX1800T/OS%20Command%20InjectExploitThird Party Advisory
FAQ
What is CVE-2025-2095?
CVE-2025-2095 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument...
How severe is CVE-2025-2095?
CVE-2025-2095 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-2095?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink Ex1800T Firmware, Totolink Ex1800T.