CVE-2026-91853 | TOTOLINK X5000R 9.1.0cu.2089_B20211224 Export Ovpn cstecgi.cgi?action=exportOvpn&type=user exportOvpn filetype os command injection

SecurityVulns

A vulnerability classified as critical has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler. The manipulation of the argument filetype leads to os command injection.

This vulnerability is documented as CVE-2026-91853. The attack can be initiated remotely. Additionally, an exploit exists.VulDB Recent EntriesRead More