CVE-2026-37152

TOTOLINK · X5000R

The TOTOLINK X5000R router contains a hardcoded password for root access, allowing unauthenticated attackers to gain full control over the device.

Executive summary

A critical hardcoded credential vulnerability in the TOTOLINK X5000R router permits unauthenticated attackers to achieve full system compromise.

Vulnerability

The device utilizes a hardcoded password for the root account, which can be leveraged by an unauthenticated attacker via network access to gain administrative privileges.

Business impact

This vulnerability carries a critical CVSS score of 9.8, indicating that it is easily exploitable with no user interaction. Successful exploitation grants an attacker full administrative access to the network infrastructure, leading to potential data interception, lateral movement into internal networks, and total system control.

Remediation

Immediate Action: Contact the vendor for firmware updates or security patches that remove the hardcoded credentials. If no patch is available, isolate the device from public internet access immediately.

Proactive Monitoring: Review device access logs for unauthorized administrative logins and monitor network traffic for suspicious activity originating from the device.

Compensating Controls: Implement strict network segmentation and firewall rules to restrict management interface access to trusted, local IP addresses only.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the research repository hosted on GitHub.

Analyst recommendation

Given the critical nature of this flaw and the availability of public proof-of-concept code, immediate action is required. Organizations utilizing the TOTOLINK X5000R should treat this as a high-priority incident, ensuring the device is not reachable from the public internet until a vendor-supplied patch is verified and applied.

More TOTOLINK CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.8 (3.1)
  4. Analyst report written

Sources