CVE-2025-13184 Details
Description
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.
An authentication bypass vulnerability has been identified in the TOTOLINK X5000R AX1800 router, specifically in the firmware version V9.1.0u.6369_B20230113. This vulnerability allows unauthenticated users to enable Telnet access, leading to root login with a blank password. The issue arises from the 'cstecgi.cgi' component, where the authentication check is bypassed, allowing arbitrary command execution with administrative privileges.
Currently, there is no firmware patch available from TOTOLINK for this vulnerability. Users are advised to segment the router from untrusted networks, monitor for unexpected Telnet traffic, and consider flashing an alternative firmware such as OpenWrt, which is supported on the X5000R hardware.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/821724 | CVE | Third Party Advisory |
| https://hackingbydoing.wixsite.com/hackingbydoing/post/totolink-x5000r-ax1800-router-authentication-bypass | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| totolink x5000r firmware | 9.1.0u.6369_b20230113 |
CPE
Remediation
| |
| totolink x5000r | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Dec 19, 2025 | Initial Analysis | [email protected] |
| Dec 10, 2025 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | CVE Modified | CVE |
| Dec 10, 2025 | New CVE Received | [email protected] |