{"schema_version":1,"title":"TOTOLINK X5000R vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 5 vulnerabilities in TOTOLINK X5000R: 0 in the last 7 days and 3 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91853, was published on 15 September 2026.","url":"https://junglewise.ai/threats/technologies/x5000r","json_url":"https://junglewise.ai/threats/technologies/x5000r.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/x5000r","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":5,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":2,"last_90_days":3,"last_365_days":5},"latest":[{"cve":"CVE-2026-91853","cvss":7.4,"epss":0.0182,"slug":"cve-2026-91853-totolink-x5000r-os-command-injection-in-exportovpn-handler","title":"TOTOLINK X5000R OS command injection in exportOvpn handler","severity":"high","exploited":false,"published_at":"2026-09-15T17:17:39.5+00:00","url":"https://junglewise.ai/threats/cve-2026-91853-totolink-x5000r-os-command-injection-in-exportovpn-handler"},{"cve":"CVE-2026-37152","cvss":9.8,"epss":0.0051,"slug":"cve-2026-37152-totolink-x5000r-hardcoded-root-password","title":"TOTOLINK X5000R hardcoded root password","severity":"critical","exploited":false,"published_at":"2026-09-15T16:17:08.533+00:00","url":"https://junglewise.ai/threats/cve-2026-37152-totolink-x5000r-hardcoded-root-password"},{"cve":"CVE-2026-15204","cvss":5.3,"slug":"cve-2026-15204-totolink-x5000r-path-traversal-in-openvpn-export","title":"TOTOLINK X5000R path traversal in OpenVPN Export","severity":"medium","exploited":false,"published_at":"2026-07-09T18:16:51.647+00:00","url":"https://junglewise.ai/threats/cve-2026-15204-totolink-x5000r-path-traversal-in-openvpn-export"},{"cve":"CVE-2025-67445","cvss":7.5,"epss":0.0035,"slug":"cve-2025-67445-totolink-x5000r-denial-of-service-in-cstecgi-cgi","title":"TOTOLINK X5000R denial of service in cstecgi.cgi","severity":"high","exploited":false,"published_at":"2026-02-24T15:21:36.707+00:00","url":"https://junglewise.ai/threats/cve-2025-67445-totolink-x5000r-denial-of-service-in-cstecgi-cgi"},{"cve":"CVE-2025-13184","cvss":9.8,"epss":0.1128,"slug":"cve-2025-13184-unauthenticated-telnet-enablement-via-cstecgi-cgi-auth-bypass","title":"Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset","severity":"critical","exploited":false,"published_at":"2025-12-10T13:16:02.97+00:00","url":"https://junglewise.ai/threats/cve-2025-13184-unauthenticated-telnet-enablement-via-cstecgi-cgi-auth-bypass"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"TOTOLINK A8000RU","slug":"a8000ru","vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/a8000ru"},{"name":"TOTOLINK CA750-PoE","slug":"ca750-poe","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/ca750-poe"},{"name":"TOTOLINK A7100RU","slug":"a7100ru","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/a7100ru"},{"name":"TOTOLINK NR1800X","slug":"nr1800x","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/nr1800x"},{"name":"TOTOLINK A3002MU","slug":"a3002mu","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/a3002mu"},{"name":"TOTOLINK A720R","slug":"a720r","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/a720r"},{"name":"TOTOLINK A720R firmware","slug":"a720r-firmware","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/a720r-firmware"},{"name":"TOTOLINK LR1200GB","slug":"lr1200gb","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/lr1200gb"},{"name":"TOTOLINK LR1200GB firmware","slug":"lr1200gb-firmware","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/lr1200gb-firmware"},{"name":"TOTOLINK N600R","slug":"n600r","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/n600r"},{"name":"TOTOLINK CP450","slug":"cp450","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/cp450"},{"name":"TOTOLINK EX1200L","slug":"ex1200l","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/ex1200l"}],"technology":{"hub":true,"name":"TOTOLINK X5000R","slug":"x5000r","vendor":{"name":"TOTOLINK","slug":"totolink","url":"https://junglewise.ai/threats/vendors/totolink"},"aliases":[],"category":"firmware","homepage":"https://www.totolink.net/home/menu/detail/menu_listpk/36/id/216.html","description":"Firmware for the TOTOLINK X5000R AX1800 Wireless Dual Band Gigabit Router.","url":"https://junglewise.ai/threats/technologies/x5000r"},"most_severe":[{"cve":"CVE-2025-13184","cvss":9.8,"epss":0.1128,"slug":"cve-2025-13184-unauthenticated-telnet-enablement-via-cstecgi-cgi-auth-bypass","title":"Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset","severity":"critical","exploited":false,"published_at":"2025-12-10T13:16:02.97+00:00","url":"https://junglewise.ai/threats/cve-2025-13184-unauthenticated-telnet-enablement-via-cstecgi-cgi-auth-bypass"},{"cve":"CVE-2026-37152","cvss":9.8,"epss":0.0051,"slug":"cve-2026-37152-totolink-x5000r-hardcoded-root-password","title":"TOTOLINK X5000R hardcoded root password","severity":"critical","exploited":false,"published_at":"2026-09-15T16:17:08.533+00:00","url":"https://junglewise.ai/threats/cve-2026-37152-totolink-x5000r-hardcoded-root-password"},{"cve":"CVE-2025-67445","cvss":7.5,"epss":0.0035,"slug":"cve-2025-67445-totolink-x5000r-denial-of-service-in-cstecgi-cgi","title":"TOTOLINK X5000R denial of service in cstecgi.cgi","severity":"high","exploited":false,"published_at":"2026-02-24T15:21:36.707+00:00","url":"https://junglewise.ai/threats/cve-2025-67445-totolink-x5000r-denial-of-service-in-cstecgi-cgi"},{"cve":"CVE-2026-91853","cvss":7.4,"epss":0.0182,"slug":"cve-2026-91853-totolink-x5000r-os-command-injection-in-exportovpn-handler","title":"TOTOLINK X5000R OS command injection in exportOvpn handler","severity":"high","exploited":false,"published_at":"2026-09-15T17:17:39.5+00:00","url":"https://junglewise.ai/threats/cve-2026-91853-totolink-x5000r-os-command-injection-in-exportovpn-handler"},{"cve":"CVE-2026-15204","cvss":5.3,"slug":"cve-2026-15204-totolink-x5000r-path-traversal-in-openvpn-export","title":"TOTOLINK X5000R path traversal in OpenVPN Export","severity":"medium","exploited":false,"published_at":"2026-07-09T18:16:51.647+00:00","url":"https://junglewise.ai/threats/cve-2026-15204-totolink-x5000r-path-traversal-in-openvpn-export"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}