CVE-2026-37152
TOTOLINK · X5000R
The TOTOLINK X5000R router contains a hardcoded password for root access, allowing unauthenticated attackers to gain full control over the device.
Executive summary
A critical hardcoded credential vulnerability in the TOTOLINK X5000R router permits unauthenticated attackers to achieve full system compromise.
Vulnerability
The device utilizes a hardcoded password for the root account, which can be leveraged by an unauthenticated attacker via network access to gain administrative privileges.
Business impact
This vulnerability carries a critical CVSS score of 9.8, indicating that it is easily exploitable with no user interaction. Successful exploitation grants an attacker full administrative access to the network infrastructure, leading to potential data interception, lateral movement into internal networks, and total system control.
Remediation
Immediate Action: Contact the vendor for firmware updates or security patches that remove the hardcoded credentials. If no patch is available, isolate the device from public internet access immediately.
Proactive Monitoring: Review device access logs for unauthorized administrative logins and monitor network traffic for suspicious activity originating from the device.
Compensating Controls: Implement strict network segmentation and firewall rules to restrict management interface access to trusted, local IP addresses only.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the research repository hosted on GitHub.
Analyst recommendation
Given the critical nature of this flaw and the availability of public proof-of-concept code, immediate action is required. Organizations utilizing the TOTOLINK X5000R should treat this as a high-priority incident, ensuring the device is not reachable from the public internet until a vendor-supplied patch is verified and applied.
More TOTOLINK CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.8 (3.1)
- Analyst report written