Home Any version before V9.1.0u.6369_B20230113
affected
Description
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
References
www.kb.cert.org/vuls/id/821724
hackingbydoing.wixsite.com/...0-router-authentication-bypass