CVE-2026-37152 Details
Description
TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.
A vulnerability exists in the TOTOLINK X5000R router, specifically in version V9.1.0cu.2415_B20250515, due to a hardcoded password for root access. This password is stored in the /etc/shadow file, allowing unauthorized users to gain root privileges. The vendor has acknowledged this vulnerability but has not provided any remediation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/AndreaLandriscina/Hardcoded-Password-Totolink-X5000R | CISA-ADP | ExploitTechnical Description |
| https://github.com/AndreaLandriscina/Hardcoded-Password-Totolink-X5000R | [email protected] | ExploitTechnical Description |
| https://github.com/AndreaLandriscina/Hardcoded-Password-Totolink-X5000R/tree/main | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| TOTOLINK X5000R | V9.1.0cu.2415_B20250515 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | [email protected] |
Volerion