X5000r
This hub aggregates every CVE we track for X5000r, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
36
CVEs tracked
5
Critical
22
High
0
In CISA KEV
Severity distribution
HIGH22MEDIUM9CRITICAL5
Monthly trend
0
0
0
0
15
1
0
0
0
0
0
0
1
0
0
1
0
3
0
0
1
0
1
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting X5000r.
- CVE-2026-15204TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal5.3
- CVE-2026-8137Totolink X5000R formDdns sub_458E40 buffer overflow8.8
- CVE-2025-67445TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (...7.5
- CVE-2025-70329TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parame...8.0
- CVE-2025-70327TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVa...9.8
- CVE-2025-14586TOTOLINK X5000R cstecgi.cgi snprintf os command injection6.3
- CVE-2025-9934TOTOLINK X5000R cstecgi.cgi sub_410C34 command injection6.3
- CVE-2025-25605Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.6.5
- CVE-2024-57023TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.6.8
- CVE-2024-57017TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg.8.8
- CVE-2024-57019TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg.8.8
- CVE-2024-57025TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCfg.6.8
- CVE-2024-57024TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg.6.8
- CVE-2024-57022TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleCfg.8.8
- CVE-2024-57021TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg.8.8
Product normalization is registry-driven with AI assist and human review. How it works