Impact
The firmware for TOTOLINK X5000R router version V9.1.0cu.2415_B20250515 contains a hardcoded password for the root account. This credential is embedded directly in the firmware binary, so any party able to retrieve or infer the password can authenticate with full administrative privileges. With root access the attacker can modify router configuration, flash malicious firmware, or monitor and tamper with network traffic, which creates a high‑risk threat to confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects TOTOLINK X5000R routers running firmware V9.1.0cu.2415_B20250515. No other vendors or products have been reported as affected at this time.
Risk and Exploitability
Because the password is hardcoded, it may be discovered from public repositories or by reverse‑engineering the firmware image. An attacker with network access to the router can perform the exploit from any connected segment. With an EPSS score of less than 1 %, the likelihood of exploitation is low, yet the guaranteed root access demands immediate remediation. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment