{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/x5000r-9.1.0cu.2089_b20211224/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:totolink:x5000r:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-91853"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["X5000R (9.1.0cu.2089_B20211224)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","cve-2026-91853","network-security"],"_cs_type":"advisory","_cs_vendors":["TOTOLINK"],"content_html":"\u003cp\u003eThe TOTOLINK X5000R router, specifically version 9.1.0cu.2089_B20211224, is susceptible to an OS command injection vulnerability (CVE-2026-91853). The vulnerability resides within the exportOvpn handler, which is invoked via the /cgi-bin/cstecgi.cgi script. An attacker can trigger this flaw by manipulating the filetype argument during an export request. Because the application fails to properly sanitize user-supplied input before passing it to the underlying system shell, an unauthenticated remote attacker can achieve arbitrary code execution. This vulnerability is publicly disclosed, increasing the risk of exploitation by opportunistic actors targeting edge network infrastructure. Defenders should monitor web server logs for suspicious requests directed at the exportOvpn handler.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to execute arbitrary operating system commands on the affected router. This could result in full device compromise, unauthorized access to internal network traffic, and the use of the router as a pivot point for further lateral movement within the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server traffic for HTTP requests targeting /cgi-bin/cstecgi.cgi with suspicious parameters in the filetype argument.\u003c/li\u003e\n\u003cli\u003eImplement access control lists on edge firewalls to restrict access to the web management interface of affected TOTOLINK routers to trusted IP ranges only.\u003c/li\u003e\n\u003cli\u003eAudit network logs for anomalous outbound connections originating from router infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T17:46:17Z","date_published":"2026-09-15T17:46:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-totolink-rce/","summary":"A remote OS command injection vulnerability in the TOTOLINK X5000R router allows unauthenticated attackers to execute arbitrary commands via the exportOvpn function.","title":"Remote Command Injection in TOTOLINK X5000R","url":"https://feed.craftedsignal.io/briefs/2026-09-totolink-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - X5000R (9.1.0cu.2089_B20211224)","version":"https://jsonfeed.org/version/1.1"}