CVE Tools

X5000R Firmware

70 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for X5000R Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

X5000R Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
X5000R Firmware CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-0115
2025-022
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-091
2025-100
2025-110
2025-122
2026-010
2026-023
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 70 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2130%
  • High3854%
  • Medium1116%

Latest CVEs

The 15 most recently published vulnerabilities affecting X5000R Firmware.

  1. CVE-2025-67445TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (...7.5
  2. CVE-2025-70327TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVa...9.8
  3. CVE-2025-70329TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parame...8.0
  4. CVE-2025-14586TOTOLINK X5000R cstecgi.cgi snprintf os command injection6.3
  5. CVE-2025-13184Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password9.8
  6. CVE-2025-9934TOTOLINK X5000R cstecgi.cgi sub_410C34 command injection6.3
  7. CVE-2025-25605Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.6.5
  8. CVE-2025-25604Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.6.5
  9. CVE-2024-57023TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.6.8
  10. CVE-2024-57017TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg.8.8
  11. CVE-2024-57013TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg.8.8
  12. CVE-2024-57011TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg.8.8
  13. CVE-2024-57012TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg.8.8
  14. CVE-2024-57021TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg.8.8
  15. CVE-2024-57018TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg.8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store