Totolink X5000R vulnerabilities
5 known vulnerabilities affecting totolink/x5000r.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-14586P1CRITICALCVSS 9.8Exploitedv9.1.0cu.2089_B202112242025-12-13
CVE-2025-14586 [CRITICAL] CWE-77 CVE-2025-14586: A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is
A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be u
nvd
CVE-2023-6612P2CRITICALCVSS 9.8v9.1.0cu.2300_B202301122023-12-08
CVE-2023-6612 [CRITICAL] CWE-78 CVE-2023-6612: A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical.
A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDynamicRoute/setFirewallType/setIPSecCfg/setIpPortFilterRules/setLancfg/setLoginPasswordCfg/setMacFilterRules/setMtknatCfg/setNetworkConfig/setPortForwardRules/setRemoteCfg/setSSServer/setScheduleCfg/setSmar
nvd
CVE-2025-9934P2CRITICALCVSS 9.8v9.1.0cu.2415_B202505152025-09-04
CVE-2025-9934 [CRITICAL] CWE-74 CVE-2025-9934: A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_4
A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
nvd
CVE-2026-8137P2HIGHCVSS 8.8v9.1.0u.6369_B202301132026-05-08
CVE-2026-8137 [HIGH] CWE-119 CVE-2026-8137: A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects
A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
nvd
CVE-2026-15204P3MEDIUMCVSS 5.3v9.1.0cu.2350_B20230313v9.1.0cu.2415_B202505152026-07-09
CVE-2026-15204 [MEDIUM] CWE-22 CVE-2026-15204: A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affec
A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerability is the function exportOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manipulation results in path traversal. The attack may be launched remotely.
nvd