Unrated severityNVD Advisory· Published Jul 9, 2026· Updated Jul 14, 2026
TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal
CVE-2026-15204
Description
A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerability is the function exportOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manipulation results in path traversal. The attack may be launched remotely.
Affected products
1Patches
Vulnerability mechanics
References
6- vuldb.com/cve/CVE-2026-15204mitrethird-party-advisory
- vuldb.com/submit/852073mitrethird-party-advisory
- github.com/meishigana/CVE/tree/main/totolink_x5000r_exportovpn_file_disclosure_2026-06-09mitrerelated
- vuldb.com/vuln/377125mitrevdb-entrytechnical-description
- vuldb.com/vuln/377125/ctimitresignaturepermissions-required
- www.totolink.netmitreproduct
News mentions
0No linked articles in our index yet.