OS Command Injection in TOTOLINK N200RE by TOTOLINK
CVE-2025-7154
Key Information:
Badges
What is CVE-2025-7154?
The TOTOLINK N200RE, specifically in versions 9.3.5u.6095_B20200916 and 9.3.5u.6139_B20201216, contains a vulnerability in the function sub_41A0F8 of the CGI script located at /cgi-bin/cstecgi.cgi. An attacker can exploit this vulnerability by manipulating the Hostname argument, which can lead to unauthorized execution of operating system commands. This can be executed remotely, making it critical for users to secure their devices against potential exploitation.
Affected Version(s)
N200RE 9.3.5u.6095_B20200916
N200RE 9.3.5u.6139_B20201216
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved