📦 X5000r Firmware

by Totolink

🔍 What is X5000r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-13184

CRITICAL CVSS 9.8 Dec 10, 2025

This critical vulnerability allows unauthenticated attackers to enable Telnet service and gain root access with blank password on Totolink X5000R routers. Attackers can execute arbitrary commands as r...

CVE-2024-32353

CRITICAL CVSS 9.8 May 14, 2024

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers by injecting malicious commands through the 'port' parameter in the setSSServer function. Attackers ...

CVE-2024-28639

CRITICAL CVSS 9.8 Mar 16, 2024

A buffer overflow vulnerability in TOTOLink routers allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted data to the IP field. This affects TOTOLin...

CVE-2023-45984

CRITICAL CVSS 9.8 Oct 16, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected TOTOLINK routers via a stack overflow in the setLanguageCfg function. Attackers can exploit this by sending specially c...

CVE-2023-39617

CRITICAL CVSS 9.8 Aug 21, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected TOTOLINK X5000R routers by sending specially crafted requests to the setLanguageCfg function's lang parameter. Attacker...

CVE-2023-31569

CRITICAL CVSS 9.8 Jun 6, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers via command injection in the setWanCfg function. Attackers can gain full control of affected devices...

CVE-2023-30013

CRITICAL CVSS 9.8 May 5, 2023

This CVE describes a command injection vulnerability in TOTOLINK X5000R routers that allows remote attackers to execute arbitrary commands via the 'command' parameter in the setTracerouteCfg endpoint....

CVE-2022-27003

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a critical command injection vulnerability in Totolink routers that allows attackers to execute arbitrary system commands via the Tunnel 6rd function. Attackers can exploit this by ...

CVE-2022-27005

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a critical command injection vulnerability in Totolink routers that allows attackers to execute arbitrary commands via the hostName parameter in the setWanCfg function. Attackers ca...

CVE-2021-45733

CRITICAL CVSS 9.8 Feb 4, 2022

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers by injecting malicious commands into the NTPSyncWithHost function's host_time parameter. Attackers c...

CVE-2021-45738

CRITICAL CVSS 9.8 Feb 4, 2022

This critical vulnerability in TOTOLINK X5000R routers allows attackers to execute arbitrary system commands through the firmware upload function. Attackers can gain complete control of affected devic...

CVE-2021-27710

CRITICAL CVSS 9.8 Apr 14, 2021

This CVE describes a critical command injection vulnerability in TOTOLINK routers that allows remote attackers to execute arbitrary operating system commands by sending specially crafted HTTP requests...

CVE-2021-27708

CRITICAL CVSS 9.8 Apr 14, 2021

This CVE describes a critical command injection vulnerability in TOTOLINK X5000R and A720R routers that allows remote attackers to execute arbitrary operating system commands by sending specially craf...

CVE-2024-57022

HIGH CVSS 8.8 Jan 15, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands through the sHour parameter in the setWiFiScheduleC...

CVE-2024-57011

HIGH CVSS 8.8 Jan 15, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands into the 'minute' parameter of the setScheduleCfg f...

CVE-2024-57012

HIGH CVSS 8.8 Jan 15, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious payloads into the 'week' parameter of the setScheduleCfg fun...

CVE-2024-57013

HIGH CVSS 8.8 Jan 15, 2025

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers where attackers can execute arbitrary commands via the 'switch' parameter in the setScheduleCfg function. This allow...

CVE-2024-57014

HIGH CVSS 8.8 Jan 15, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands through the 'recHour' parameter in the setScheduleC...

CVE-2024-57015

HIGH CVSS 8.8 Jan 15, 2025

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers where attackers can execute arbitrary commands via the 'hour' parameter in the setScheduleCfg function. This allows ...

CVE-2024-57016

HIGH CVSS 8.8 Jan 15, 2025

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers where an attacker can execute arbitrary commands via the 'user' parameter in the setVpnAccountCfg function. This all...

CVE-2024-57017

HIGH CVSS 8.8 Jan 15, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands through the 'pass' parameter in the setVpnAccountCf...

CVE-2024-57018

HIGH CVSS 8.8 Jan 15, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands through the 'desc' parameter in the setVpnAccountCf...

CVE-2024-57019

HIGH CVSS 8.8 Jan 15, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands through the 'limit' parameter in the setVpnAccountC...

CVE-2024-57020

HIGH CVSS 8.8 Jan 15, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands through the sMinute parameter in the setWiFiSchedul...

CVE-2024-57021

HIGH CVSS 8.8 Jan 15, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands through the eHour parameter in the setWiFiScheduleC...

CVE-2024-42737

HIGH CVSS 8.8 Aug 13, 2024

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on TOTOLINK X5000r routers through command injection in the delBlacklist function. Attackers can gain f...

CVE-2024-42739

HIGH CVSS 8.8 Aug 13, 2024

This CVE describes an authenticated OS command injection vulnerability in TOTOLINK X5000r routers. Attackers with valid credentials can execute arbitrary commands on the device by sending malicious pa...

CVE-2024-42743

HIGH CVSS 8.8 Aug 12, 2024

This CVE describes an OS command injection vulnerability in TOTOLINK X5000r routers that allows authenticated attackers to execute arbitrary commands on the device. The vulnerability exists in the set...

CVE-2024-42745

HIGH CVSS 8.8 Aug 12, 2024

This CVE describes an authenticated OS command injection vulnerability in TOTOLINK X5000r routers. Attackers with valid credentials can send specially crafted packets to execute arbitrary commands on ...

CVE-2024-42748

HIGH CVSS 8.8 Aug 12, 2024

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on TOTOLINK X5000r routers through command injection in the WiFi WPS configuration function. Attackers ...

CVE-2024-42741

HIGH CVSS 8.8 Aug 12, 2024

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on TOTOLINK X5000r routers by sending malicious packets to a specific CGI endpoint. Attackers with vali...

CVE-2024-32352

HIGH CVSS 8.8 May 14, 2024

This vulnerability allows authenticated attackers to execute arbitrary commands on TOTOLINK X5000R routers by manipulating the ipsecL2tpEnable parameter in the cstecgi.cgi binary. It affects users run...

CVE-2024-32355

HIGH CVSS 8.0 May 14, 2024

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers by injecting malicious commands into the 'password' parameter of the setSSServer function. Attackers...

CVE-2024-32350

HIGH CVSS 8.8 May 14, 2024

This vulnerability allows authenticated attackers to execute arbitrary commands on TOTOLINK X5000R routers by exploiting improper input validation in the ipsecPsk parameter. Attackers with valid crede...

CVE-2024-34921

HIGH CVSS 8.8 May 14, 2024

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers via the disconnectVPN function. Attackers can gain full control of affected devices, potentially com...

CVE-2021-45735

HIGH CVSS 7.5 Feb 4, 2022

This vulnerability allows attackers to intercept administrator credentials for TOTOLINK X5000R routers because the admin interface uses unencrypted HTTP instead of HTTPS. Anyone using the affected rou...

CVE-2025-14586

MEDIUM CVSS 6.3 Dec 13, 2025

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers. Attackers can exploit the 'exportOvpn' function via the web interface to execute arbitrary commands on the device. ...

CVE-2025-9934

MEDIUM CVSS 6.3 Sep 4, 2025

This CVE describes a command injection vulnerability in TOTOLINK X5000R routers affecting the sub_410C34 function in the cgi-bin/cstecgi.cgi file. Attackers can manipulate the 'pid' argument to execut...

CVE-2025-25605

MEDIUM CVSS 6.5 Feb 21, 2025

This vulnerability allows remote attackers to execute arbitrary commands on Totolink X5000R routers through command injection in the apcli_wps_gen_pincode function. Attackers can gain full control of ...

CVE-2024-57023

MEDIUM CVSS 6.8 Jan 15, 2025

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers where an attacker can execute arbitrary commands via the 'week' parameter in the setWiFiScheduleCfg function. This a...

CVE-2024-57025

MEDIUM CVSS 6.8 Jan 15, 2025

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers via the 'desc' parameter in the setWiFiScheduleCfg function. Attackers can execute arbitrary commands with router pr...