CVE-2025-13184 is a critical authentication bypass vulnerability affecting the TOTOLINK X5000R (AX1800) router, confirmed on firmware version V9.1.0u.6369_B20230113; earlier versions sharing the same implementation may also be affected. The flaw is in the device management interface, specifically the /cgi-bin/cstecgi.cgi?action=telnet functionality, where insufficient authentication checks allow an unauthenticated attacker to enable the Telnet service with a single HTTP request. On factory-reset or default-state devices, the attacker can then connect over Telnet and log in as root with a blank password, resulting in arbitrary command execution on the router.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass / improper access control vulnerability in the TOTOLINK X5000R management interface that can allow full device compromise, unauthenticated enabling of Telnet, and root login without a password.
An authentication bypass / improper access control vulnerability in the TOTOLINK X5000R management interface that can allow full device compromise, unauthenticated enabling of Telnet, and root login without a password.
A critical authentication bypass and remote code execution vulnerability in the TOTOLINK AX1800 router allows unauthenticated attackers to enable Telnet and gain root access via a single HTTP request. No patch is currently available.
A critical authentication bypass vulnerability in the cstecgi.cgi component allows unauthenticated attackers to enable Telnet and gain root access with a blank password on certain TOTOLINK X5000R routers, leading to arbitrary command execution. The flaw is remotely exploitable and affects at least firmware version V9.1.0u.6369_B20230113, with earlier versions potentially impacted.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.