Totolink
Totolink X5000r Firmware: vulnerabilidades y CVE
Totolink X5000r Firmware tiene 70 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 22 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE70
Últimos 12 meses5
Críticas22
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-67445 | Alta (7.5) | 0.35% | — | 24 feb 2026 | TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (CONTENT_LENGTH + 1)… |
| CVE-2025-70327 | Crítica (9.8) | 0.72% | — | 23 feb 2026 | TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping… |
| CVE-2025-70329 | Alta (8) | 3.3% | — | 23 feb 2026 | TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via… |
| CVE-2025-14586 | Baja (2.1) | 2.8% | — | 13 dic 2025 | A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument… |
| CVE-2025-13184 | Crítica (9.8) | 11% | — | 10 dic 2025 | Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions… |
| CVE-2025-9934 | Baja (2.1) | 3.7% | — | 4 sept 2025 | A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection.… |
| CVE-2025-25605 | Media (6.5) | 0.79% | — | 21 feb 2025 | Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua. |
| CVE-2025-25604 | Media (6.5) | 0.79% | — | 21 feb 2025 | Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua. |
| CVE-2024-57025 | Media (6.8) | 1.4% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCfg. |
| CVE-2024-57024 | Media (6.8) | 1.5% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg. |
| CVE-2024-57023 | Media (6.8) | 1.4% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg. |
| CVE-2024-57022 | Alta (8.8) | 1.6% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleCfg. |
| CVE-2024-57021 | Alta (8.8) | 1.6% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg. |
| CVE-2024-57020 | Alta (8.8) | 1.6% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in setWiFiScheduleCfg. |
| CVE-2024-57019 | Alta (8.8) | 1.6% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg. |
| CVE-2024-57018 | Alta (8.8) | 1.6% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg. |
| CVE-2024-57017 | Alta (8.8) | 1.6% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg. |
| CVE-2024-57016 | Alta (8.8) | 1.6% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg. |
| CVE-2024-57015 | Alta (8.8) | 1.6% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg. |
| CVE-2024-57014 | Alta (8.8) | 1.2% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg. |
| CVE-2024-57013 | Alta (8.8) | 1.6% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg. |
| CVE-2024-57012 | Alta (8.8) | 1.6% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg. |
| CVE-2024-57011 | Alta (8.8) | 1.7% | — | 15 ene 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg. |
| CVE-2024-42740 | Media (6.8) | 2.7% | — | 13 ago 2024 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. |
| CVE-2024-42739 | Alta (8.8) | 1.6% | — | 13 ago 2024 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary… |
| CVE-2024-42738 | Alta (8.8) | 1.6% | — | 13 ago 2024 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. |
| CVE-2024-42737 | Alta (8.8) | 1.7% | — | 13 ago 2024 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands. |
| CVE-2024-42736 | Alta (7.8) | 1.6% | — | 13 ago 2024 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands. |
| CVE-2024-42748 | Alta (8.8) | 1.7% | — | 12 ago 2024 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. |
| CVE-2024-42747 | Alta (8.8) | 1.1% | — | 12 ago 2024 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.