Home

Description

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.

PUBLISHED Reserved 2025-11-14 | Published 2025-12-10 | Updated 2025-12-10 | Assigner certcc

Problem types

CWE-306 Missing Authentication for Critical Function

Product status

Any version before V9.1.0u.6369_B20230113
affected

References

www.kb.cert.org/vuls/id/821724

hackingbydoing.wixsite.com/...0-router-authentication-bypass

cve.org (CVE-2025-13184)

nvd.nist.gov (CVE-2025-13184)

Download JSON