A critical vulnerability, tracked as CVE-2025-13184, has been discovered in the TOTOLINK AX1800 wireless router, allowing remote attackers to bypass authentication and enable the Telnet service via a crafted HTTP request to the /cgi-bin/cstecgi.cgi?action=telnet endpoint. This flaw permits unauthenticated users to gain root-level access to the device, enabling arbitrary command execution and full administrative control without requiring a password. The vulnerability affects at least the X5000R V9.1.0u.6369_B20230113 firmware and potentially earlier versions with similar implementations, and there is currently no official patch available.
With root access, attackers can modify DNS settings, intercept network traffic, and use the compromised router as a foothold for further attacks within the local network. The CERT Coordination Center has issued an advisory warning of the severe implications, including the risk of lateral movement and persistent compromise if the router's management interface is exposed to the internet. The vulnerability is rated as critical (CVSS 9.8), and users are urged to restrict remote access and monitor for suspicious activity until a fix is released.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Follow-up reporting emphasized that no official vendor patch was available for CVE-2025-13184 at the time, leaving affected users dependent on mitigations rather than a firmware fix. The issue was described as posing serious risk to home and small-business networks if management access was exposed.
Advisories noted that public proof-of-concept exploit details for CVE-2025-13184 were available online, increasing the likelihood of exploitation. CERT/CC and related guidance recommended mitigations such as disabling Telnet, restricting WAN access, changing default credentials, and monitoring for unexpected Telnet activity.
A critical vulnerability, CVE-2025-13184, was published affecting the TOTOLINK X5000R V9.1.0u.6369_B20230113 router. The flaw allows unauthenticated attackers to enable Telnet through cstecgi.cgi and log in as root with a blank password, enabling remote command execution on default or factory-reset devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.