Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.
Metrics
Affected Vendors & Products
References
History
Fri, 19 Dec 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink x5000r Firmware
|
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:h:totolink:x5000r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:x5000r_firmware:9.1.0u.6369_b20230113:*:*:*:*:*:*:* |
|
| Vendors & Products |
Totolink x5000r Firmware
|
Wed, 10 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink
Totolink x5000r |
|
| Vendors & Products |
Totolink
Totolink x5000r |
Wed, 10 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 10 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 10 Dec 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected. | |
| Title | Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published: 2025-12-10T12:34:54.590Z
Updated: 2025-12-10T15:21:20.666Z
Reserved: 2025-11-14T12:22:56.010Z
Link: CVE-2025-13184
Updated: 2025-12-10T13:17:29.972Z
Status : Analyzed
Published: 2025-12-10T13:16:02.970
Modified: 2025-12-19T19:27:20.293
Link: CVE-2025-13184
No data.