Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-70327

Опубликовано: 23 фев. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping command through CsteSystem without validating if the input starts with a hyphen (-). This allows remote authenticated attackers to inject arbitrary command-line options into the ping utility, potentially leading to a Denial of Service (DoS) by causing excessive resource consumption or prolonged execution.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:totolink:x5000r_firmware:9.1.0cu.2415_b20250515:*:*:*:*:*:*:*
cpe:2.3:h:totolink:x5000r:-:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00693
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-88
CWE-400

Связанные уязвимости

CVSS3: 9.8
github
6 месяцев назад

TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping command through CsteSystem without validating if the input starts with a hyphen (-). This allows remote authenticated attackers to inject arbitrary command-line options into the ping utility, potentially leading to a Denial of Service (DoS) by causing excessive resource consumption or prolonged execution.

CVSS3: 9.8
fstec
10 месяцев назад

Уязвимость обработчика setDiagnosisCfg исполняемого файла /usr/sbin/lighttpd микропрограммного обеспечения роутеров TOTOLINK X5000R, позволяющая нарушителю внедрять произвольные параметры командной строки

EPSS

Процентиль: 50%
0.00693
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-88
CWE-400