X5000R
37 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for X5000R, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
X5000R CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 15 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 3 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 37 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical5
- High23
- Medium9
Latest CVEs
The 15 most recently published vulnerabilities affecting X5000R.
- CVE-2026-91853TOTOLINK X5000R Export Ovpn cstecgi.cgi exportOvpn os command injection7.4
- CVE-2026-15204TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal5.3
- CVE-2026-8137Totolink X5000R formDdns sub_458E40 buffer overflow8.8
- CVE-2025-67445TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (...7.5
- CVE-2025-70327TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVa...9.8
- CVE-2025-70329TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parame...8.0
- CVE-2025-14586TOTOLINK X5000R cstecgi.cgi snprintf os command injection6.3
- CVE-2025-9934TOTOLINK X5000R cstecgi.cgi sub_410C34 command injection6.3
- CVE-2025-25605Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.6.5
- CVE-2024-57023TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.6.8
- CVE-2024-57017TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg.8.8
- CVE-2024-57013TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg.8.8
- CVE-2024-57011TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg.8.8
- CVE-2024-57012TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg.8.8
- CVE-2024-57021TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg.8.8
Product grouping is registry-driven, with AI assist and human review. How it works