Vulnerability Description
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | X5000R Firmware | 9.1.0u.6369_b20230113 |
| Totolink | X5000R | - |
Related Weaknesses (CWE)
References
- https://hackingbydoing.wixsite.com/hackingbydoing/post/totolink-x5000r-ax1800-roExploitThird Party Advisory
- https://www.kb.cert.org/vuls/id/821724Third Party Advisory
FAQ
What is CVE-2025-13184?
CVE-2025-13184 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution)...
How severe is CVE-2025-13184?
CVE-2025-13184 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-13184?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink X5000R Firmware, Totolink X5000R.