cbcvebase.

Totolink X5000R Firmware vulnerabilities

70 known vulnerabilities affecting totolink/x5000r_firmware.

Total CVEs
70
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL24HIGH38MEDIUM8

Vulnerabilities

Page 1 of 4
CVE-2025-14586P1CRITICALCVSS 9.8Exploitedv9.1.0cu.2089_b202112242025-12-13
CVE-2025-14586 [CRITICAL] CWE-77 CVE-2025-14586: A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be u
nvd
CVE-2023-30013P2CRITICALCVSS 9.8PoCv9.1.0u.6118_b20201102v9.1.0u.6369_b202301132023-05-05
CVE-2023-30013 [CRITICAL] CWE-78 CVE-2023-30013: TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulner TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.
nvd
CVE-2023-6612P2CRITICALCVSS 9.8v9.1.0cu.2300_b202301122023-12-08
CVE-2023-6612 [CRITICAL] CWE-78 CVE-2023-6612: A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDynamicRoute/setFirewallType/setIPSecCfg/setIpPortFilterRules/setLancfg/setLoginPasswordCfg/setMacFilterRules/setMtknatCfg/setNetworkConfig/setPortForwardRules/setRemoteCfg/setSSServer/setScheduleCfg/setSmar
nvd
CVE-2025-13184P2CRITICALCVSS 9.8v9.1.0u.6369_b202301132025-12-10
CVE-2025-13184 [CRITICAL] CWE-863 CVE-2025-13184: Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root logi Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.
nvd
CVE-2022-26213P2CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-03-15
CVE-2022-26213 [CRITICAL] CWE-78 CVE-2022-26213: Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulner Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-9934P2CRITICALCVSS 9.8v9.1.0cu.2415_b202505152025-09-04
CVE-2025-9934 [CRITICAL] CWE-74 CVE-2025-9934: A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_4 A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
nvd
CVE-2021-27710P2CRITICALCVSS 9.8v9.1.0u.6118_b202011022021-04-14
CVE-2021-27710 [CRITICAL] CWE-78 CVE-2021-27710: Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "ip" pa
nvd
CVE-2022-27005P2CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-03-15
CVE-2022-27005 [CRITICAL] CWE-78 CVE-2022-27005: Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered t Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2021-27708P2CRITICALCVSS 9.8v9.1.0u.6118_b202011022021-04-14
CVE-2021-27708 [CRITICAL] CWE-78 CVE-2021-27708: Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "comman
nvd
CVE-2022-27004P2CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-03-15
CVE-2022-27004 [CRITICAL] CWE-78 CVE-2022-27004: Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered t Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2022-27003P2CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-03-15
CVE-2022-27003 [CRITICAL] CWE-78 CVE-2022-27003: Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered t Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2024-32353P2CRITICALCVSS 9.8v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32353 [CRITICAL] CWE-77 CVE-2024-32353: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.
nvd
CVE-2021-45733P2CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-02-04
CVE-2021-45733 [CRITICAL] CWE-77 CVE-2021-45733: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability i TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.
nvd
CVE-2021-45738P2CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-02-04
CVE-2021-45738 [CRITICAL] CWE-77 CVE-2021-45738: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability i TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.
nvd
CVE-2023-31569P2CRITICALCVSS 9.8v9.1.0cu.2350_b202303132023-06-06
CVE-2023-31569 [CRITICAL] CWE-77 CVE-2023-31569: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWan TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
nvd
CVE-2023-33487P2CRITICALCVSS 9.8v9.1.0u.6118_b20201102v9.1.0u.6369_b202301132023-05-31
CVE-2023-33487 [CRITICAL] CWE-77 CVE-2023-33487: TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulne TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter.
nvd
CVE-2024-34921P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132024-05-14
CVE-2024-34921 [HIGH] CWE-78 CVE-2024-34921: TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the discon TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.
nvd
CVE-2023-33486P2CRITICALCVSS 9.8v9.1.0u.6118_b20201102v9.1.0u.6369_b202301132023-05-31
CVE-2023-33486 [CRITICAL] CWE-77 CVE-2023-33486: TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulner TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.
nvd
CVE-2024-42737P2HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-13
CVE-2024-42737 [HIGH] CWE-78 CVE-2024-42737: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42745P2HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42745 [HIGH] CWE-78 CVE-2024-42745: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
Totolink X5000R Firmware vulnerabilities | cvebase