cbcvebase.

Totolink X5000R Firmware vulnerabilities

70 known vulnerabilities affecting totolink/x5000r_firmware.

Total CVEs
70
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL24HIGH38MEDIUM8

Vulnerabilities

Page 3 of 4
CVE-2023-36950P2CRITICALCVSS 9.8v9.1.0u.6118_b202011022023-10-16
CVE-2023-36950 [CRITICAL] CWE-787 CVE-2023-36950: TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
nvd
CVE-2023-45984P3CRITICALCVSS 9.8v9.1.0u.6118_b202011022023-10-16
CVE-2023-45984 [CRITICAL] CWE-787 CVE-2023-45984: TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.
nvd
CVE-2025-70327P2CRITICALCVSS 9.8v9.1.0cu.2415_b202505152026-02-23
CVE-2025-70327 [CRITICAL] CWE-88 CVE-2025-70327: TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagn TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping command through CsteSystem without validating if the input starts with a hyphen (-). This allows remote authenticated attackers to
nvd
CVE-2025-70329P3HIGHCVSS 8.0v9.1.0cu.2415_b202505152026-02-23
CVE-2025-70329 [HIGH] CWE-78 CVE-2025-70329: TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIpt TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without adequate validation or filtering. This allows an authenticated attacker to e
nvd
CVE-2024-42747P2HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42747 [HIGH] CWE-78 CVE-2024-42747: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2023-36947P3CRITICALCVSS 9.8v9.1.0u.6118_b202011022023-10-16
CVE-2023-36947 [CRITICAL] CWE-787 CVE-2023-36947: TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
nvd
CVE-2024-32350P3HIGHCVSS 8.8v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32350 [HIGH] CWE-94 CVE-2024-32350: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command ex TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.
nvd
CVE-2024-32352P3HIGHCVSS 8.8v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32352 [HIGH] CWE-94 CVE-2024-32352: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command ex TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary.
nvd
CVE-2024-32351P3HIGHCVSS 8.8v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32351 [HIGH] CWE-78 CVE-2024-32351: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command ex TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mru" parameter in the "cstecgi.cgi" binary.
nvd
CVE-2023-39618P3CRITICALCVSS 9.8vb202104192023-08-21
CVE-2023-39618 [CRITICAL] CWE-77 CVE-2023-39618: TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface.
nvd
CVE-2024-28639P3CRITICALCVSS 9.8v9.1.0u.6118_b202011022024-03-16
CVE-2024-28639 [CRITICAL] CWE-120 CVE-2024-28639: Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B202 Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field.
nvd
CVE-2023-33485P3HIGHCVSS 8.8v9.1.0u.6118_b20201102v9.1.0u.6369_b202301132023-05-31
CVE-2023-33485 [HIGH] CWE-787 CVE-2023-33485: TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buf TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function.
nvd
CVE-2024-32355P3HIGHCVSS 8.0v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32355 [HIGH] CWE-77 CVE-2024-32355: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.
nvd
CVE-2021-45735P3HIGHCVSS 7.5v9.1.0u.6118_b202011022022-02-04
CVE-2021-45735 [HIGH] CWE-319 CVE-2021-45735: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication in TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.
nvd
CVE-2024-42736P3HIGHCVSS 7.8v9.1.0cu.2350_b202303132024-08-13
CVE-2024-42736 [HIGH] CWE-78 CVE-2024-42736: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-28640P3HIGHCVSS 7.5v9.1.0u.6118_b202011022024-03-16
CVE-2024-28640 [HIGH] CWE-125 CVE-2024-28640: Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B202 Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.
nvd
CVE-2025-67445P3HIGHCVSS 7.5v9.1.0cu.2415_b202505152026-02-24
CVE-2025-67445 [HIGH] CWE-400 CVE-2025-67445: TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstec TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (CONTENT_LENGTH + 1) without sufficient bounds checking. When lighttpd s request size limit is not enforced, a crafted large POST request can cause memory ex
nvd
CVE-2024-42740P3MEDIUMCVSS 6.8v9.1.0cu.2350_b202303132024-08-13
CVE-2024-42740 [MEDIUM] CWE-78 CVE-2024-42740: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2025-25605P3MEDIUMCVSS 6.5v9.1.0u.6369_b202301132025-02-21
CVE-2025-25605 [MEDIUM] CWE-77 CVE-2025-25605: Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pinc Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.
nvd
CVE-2025-25604P3MEDIUMCVSS 6.5v9.1.0u.6369_b202301132025-02-21
CVE-2025-25604 [MEDIUM] CWE-77 CVE-2025-25604: Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable functi Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.
nvd