CVE-2025-13184 PUBLISHED

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password

Assigner: certcc
Reserved: 14.11.2025 Published: 10.12.2025 Updated: 10.12.2025

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.

Product Status

Vendor Toto Link
Product X5000R's (AX1800 router)
Versions
  • affected from 0 to V9.1.0u.6369_B20230113 (excl.)

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function