CVE Explorer
CVE-2025-70329
TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without adequate validation or filtering. This allows an authenticated attacker to execute arbitrary shell commands with root privileges by injecting shell metacharacters into the affected parameters.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:935f57d1554488d6d50cc1ff79586eec14dd789ec0fbaa455d6ff72980eab9d4 · sha256:c7404dfce5fa94c6… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:935f57d1554488d6d50cc1ff79586eec14dd789ec0fbaa455d6ff72980eab9d4 · sha256:c7404dfce5fa94c6… · /containers/adp/0/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:935f57d1554488d6d50cc1ff79586eec14dd789ec0fbaa455d6ff72980eab9d4 · sha256:c7404dfce5fa94c6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:935f57d1554488d6d50cc1ff79586eec14dd789ec0fbaa455d6ff72980eab9d4 · sha256:c7404dfce5fa94c6… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:935f57d1554488d6d50cc1ff79586eec14dd789ec0fbaa455d6ff72980eab9d4 · sha256:c7404dfce5fa94c6… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:935f57d1554488d6d50cc1ff79586eec14dd789ec0fbaa455d6ff72980eab9d4 · sha256:c7404dfce5fa94c6… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://github.com/neighborhood-H/0-DAY/blob/main/Toto-link/X5000R/SetIptvCfg/report.md"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:935f57d1554488d6d50cc1ff79586eec14dd789ec0fbaa455d6ff72980eab9d4 · sha256:c7404dfce5fa94c6… · /containers/cna/references/1
{"url":"https://www.notion.so/TOTOLINK-X5000R-SetIptvCfg-2d170566ca7f8027ad47e6b5429025fc?source=copy_link"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:935f57d1554488d6d50cc1ff79586eec14dd789ec0fbaa455d6ff72980eab9d4 · sha256:c7404dfce5fa94c6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.