漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal
Vulnerability Description
A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerability is the function exportOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manipulation results in path traversal. The attack may be launched remotely.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
TOTOLINK x5000r firmware 路径遍历漏洞
Vulnerability Description
TOTOLINK x5000r firmware是中国TOTOLINK公司的一款无线路由器的固件升级程序。 TOTOLINK x5000r firmware 9.1.0cu.2415_B20250515版本和9.1.0cu.2350_B20230313版本存在路径遍历漏洞,该漏洞源于文件/web/cgi-bin/cstecgi.cgi中OpenVPN Export组件的exportOvpn函数存在路径遍历问题,可能导致远程攻击。
CVSS Information
N/A
Vulnerability Type
N/A