X5000R
TOTOLINK- Software type
- —
- Catalog vulnerabilities
- 5
Severity across 2 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 2 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 5 vulnerability records affecting X5000R.
Among the 2 records analyzed by CyStack, 1 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-15204TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal | Exploitation statusPublic exploit | FixNot confirmed | Published07/09/2026 | SeverityMedium |
CVE-2026-8137Totolink X5000R formDdns sub_458E40 buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published05/08/2026 | SeverityHigh |
CVE-2025-14586TOTOLINK X5000R cstecgi.cgi snprintf os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published12/13/2025 | SeverityMedium |
CVE-2025-9934TOTOLINK X5000R cstecgi.cgi sub_410C34 command injection | Exploitation statusPublic exploit | FixNot confirmed | Published09/03/2025 | SeverityMedium |
CVE-2023-6612Totolink X5000R cstecgi.cgi setWizardCfg os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published12/08/2023 | SeverityMedium |