TOTOLINK X5000R firmware V9.1.0cu.2415_B20250515 contains a denial-of-service condition in the management CGI endpoint /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates a request buffer using malloc(CONTENT_LENGTH + 1) without sufficient bounds checking. If the front-end web server (lighttpd) request size limit is not enforced, an attacker can send an oversized crafted POST request such that the CGI attempts to allocate an excessively large buffer, resulting in memory exhaustion and/or a segmentation fault. This crashes the management CGI and causes loss of availability of the web management interface.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python PoC (poc.py) and a README describing an unauthenticated LAN-side DoS against TOTOLINK X5000R V9.1.0cu.2415. The exploit works by sending increasingly large HTTP POST requests with JSON to the router’s management CGI endpoint /cgi-bin/cstecgi.cgi. The README explains the root cause: Lighttpd’s request size limit (server.max-request-size) is commented out, allowing very large bodies; the CGI handler trusts the user-controlled CONTENT_LENGTH and performs malloc(CONTENT_LENGTH+1), which can exceed device RAM (noted as 256MB) and lead to a segmentation fault and crash of the web service. poc.py hardcodes the target URL as http://127.0.0.1/cgi-bin/cstecgi.cgi (intended to be changed to the router’s LAN IP). It constructs a JSON object with topicurl=getInitCfg and a token string that grows exponentially (multiplied by 8 each loop) until the encoded JSON reaches ~256MB, sending each payload via urllib.request with Content-Type: application/json. The script prints the computed CONTENT_LENGTH (based on encoded JSON size), sends the request with a short timeout, sleeps 1 second between rounds, and continues until the size threshold is reached—aiming to exhaust memory and crash the management interface. No code for RCE, authentication bypass, or persistence is present; the capability is strictly DoS via oversized request bodies.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.