A critical vulnerability, CVE-2025-13184, in the TOTOLINK X5000R (AX1800) home router allows an attacker with access to the device’s management interface—or physical access to the router—to enable Telnet without authentication and log in as root with no password. The flaw was confirmed in firmware version V9.1.0u.6369_B20230113, and earlier versions may also be affected. Publicly known exploitation can lead to full device compromise, arbitrary code execution, configuration tampering, traffic manipulation, exposure of sensitive network data, botnet enrollment, and lateral movement to other devices on the local network.
No vendor patch was reported as available at the time of publication, prompting guidance to treat the X5000R as untrusted from an access-control perspective and avoid connecting it directly to the internet. Recommended mitigations include keeping the management panel inaccessible from the public internet, verifying network segmentation and cabling, replacing the firmware with an alternative such as OpenWrt where feasible, or removing and securely disposing of the device if the risk cannot be managed. A key indicator of compromise is TCP port 23 being open on the router, suggesting Telnet has been enabled maliciously.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
By the time of disclosure, the exploitation method for CVE-2025-13184 was publicly known and no vendor patch was reported as available. CERT/CC and Traficom recommended treating the router as untrusted, avoiding internet exposure of the management panel, and considering mitigations such as network segmentation, alternative firmware, or device replacement.
A critical vulnerability, CVE-2025-13184, was publicly reported for the TOTOLINK X5000R (AX1800) router. The flaw allows an attacker with access to the management interface or physical access to enable Telnet without authentication and log in as root without a password, leading to possible full device compromise.
Firmware version V9.1.0u.6369_B20230113 was described as the latest available version as of October 2025, and it was confirmed to be affected by CVE-2025-13184. Earlier firmware versions were also considered potentially vulnerable.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.