Critical severity9.8NVD Advisory· Published Dec 10, 2025· Updated Jun 17, 2026
CVE-2025-13184
CVE-2025-13184
Description
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Toto Link/X5000R's (AX1800 router)v5Range: 0
- cpe:2.3:o:totolink:x5000r_firmware:9.1.0u.6369_b20230113:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- hackingbydoing.wixsite.com/hackingbydoing/post/totolink-x5000r-ax1800-router-authentication-bypassnvdExploitThird Party Advisory
- www.kb.cert.org/vuls/id/821724nvdThird Party Advisory
News mentions
0No linked articles in our index yet.