CVE-2025-70329 | Totolink X5000R 9.1.0cu_2415_B20250515 /usr/sbin/lighttpd CsteSystem vlanVidLan1 os command injection
A vulnerability identified as critical has been detected in Totolink X5000R 9.1.0cu_2415_B20250515. Affected by this issue is the function CsteSystem of the file /usr/sbin/lighttpd. The manipulation of the argument vlanVidLan1 leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-70329. The attack is possible to be carried out remotely. No exploit exists.