← Back to browse · API

CVE-2025-13184

Severity
CRITICAL
CVSS
9.8
EPSS
0.11278
Risk score
43.15
CISA KEV
No
PoC
No
Published
2025-12-10
Modified
2025-12-10
First seen
2026-08-07
Aliases
CNVD-2026-03712, EUVD-2025-202419, GHSA-XR55-5XVM-9RW7
Products
TOTOLINK X5000R V9.1.0u.6369_B20230113, Toto Link:X5000R's (AX1800 router) 0 <V9.1.0u.6369_B20230113
Sources
cnvd CNVD-2026-03712
euvd EUVD-2025-202419

Description

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.

References