Junglewise Threat Intelligence

CVE-2025-9577: TOTOLINK X2000R use of default credentials in administrative interface

CVE-2025-9577 · Severity: low · CVSS 2.5 · Published 2025-08-28

Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the TOTOLINK X2000R Wi-Fi 6 router due to the use of a weak, easily guessable default password for the root administrator account. An attacker who can access the device's management interface could use these credentials to take full control of the router. This could lead to the theft of sensitive network data, modification of internet settings, or the use of the device as a foothold for further attacks on the local network.

Technical details

The TOTOLINK X2000R Wi-Fi 6 router contains a hardcoded or insecure default password for the root user account. The vulnerability stems from the file /etc/shadow.sample, which stores the root password hash using MD5-crypt. Security researchers successfully cracked this hash to reveal a weak password ('123456'). While some initial reports categorized this as a local attack, the researcher's analysis indicates that the credentials can be used to log in via network-accessible services or the web-based administrative interface. Successful exploitation grants the attacker full root-level privileges, enabling arbitrary code execution and complete device compromise.

Affected products

  • TOTOLINK X2000R firmware up to 2.0.0-B20230727.1043.web

Timeline

  • 2025-08-28: disclosed: Initial public disclosure and CVE assignment

References