CVE Tools

X2000R Firmware

45 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for X2000R Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

X2000R Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
X2000R Firmware CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-065
2025-071
2025-081
2025-091
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 45 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2862%
  • High511%
  • Medium818%
  • Low49%

Latest CVEs

The 15 most recently published vulnerabilities affecting X2000R Firmware.

  1. CVE-2025-57579An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password8.0
  2. CVE-2025-9577TOTOLINK X2000R Administrative shadow.sample default credentials2.5
  3. CVE-2025-8181TOTOLINK N600R/X2000R FTP Service vsftpd.conf least privilege violation7.2
  4. CVE-2025-5543TOTOLINK X2000R Parent Controls Page cross site scripting2.4
  5. CVE-2025-5542TOTOLINK X2000R Virtual Server Page formPortFw cross site scripting2.4
  6. CVE-2025-5516TOTOLINK X2000R URL Filtering Page formFilter cross site scripting2.4
  7. CVE-2025-5515TOTOLINK X2000R formMapDel command injection6.3
  8. CVE-2025-5504TOTOLINK X2000R formWsc command injection6.3
  9. CVE-2024-33433Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.4.8
  10. CVE-2024-28402TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.5.9
  11. CVE-2024-29419There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013.5.4
  12. CVE-2024-28403TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.5.4
  13. CVE-2024-28404TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.8.0
  14. CVE-2024-28401TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page.5.4
  15. CVE-2024-22529TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store