VYPR

X5000r Firmware

by Totolink

Source repositories

CVEs (70)

  • CVE-2024-57024MedJan 15, 2025
    risk 0.44cvss 6.8epss 0.02

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg.

  • CVE-2024-57023MedJan 15, 2025
    risk 0.44cvss 6.8epss 0.01

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.

  • CVE-2024-42740MedAug 13, 2024
    risk 0.44cvss 6.8epss 0.03

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

  • CVE-2025-25605MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.01

    Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.

  • CVE-2025-25604MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.01

    Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.

  • CVE-2025-14586MedDec 13, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os command injection. Remote exploitation of the…

  • CVE-2025-9934MedSep 4, 2025
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has…

  • CVE-2024-32354MedMay 14, 2024
    risk 0.39cvss 6.0epss 0.01

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.

  • CVE-2024-32349MedMay 14, 2024
    risk 0.39cvss 6.0epss 0.01

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.

  • CVE-2023-6612MedDec 8, 2023
    risk 0.38cvss 5.5epss 0.31

    A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDynamicRoute/setFirewallType/setIPSecCfg/setIpPortFilterRules/setLancfg/setLoginPasswordCfg/setMacFilterRules/setMtknatCfg/setNetworkC…

Page 4 of 4