Description
TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized root access via hardcoded password
Action: Update Firmware
AI Analysis

Impact

The firmware for TOTOLINK X5000R router version V9.1.0cu.2415_B20250515 contains a hardcoded password for the root account. This credential is embedded directly in the firmware binary, so any party able to retrieve or infer the password can authenticate with full administrative privileges. With root access the attacker can modify router configuration, flash malicious firmware, or monitor and tamper with network traffic, which creates a high‑risk threat to confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects TOTOLINK X5000R routers running firmware V9.1.0cu.2415_B20250515. No other vendors or products have been reported as affected at this time.

Risk and Exploitability

Because the password is hardcoded, it may be discovered from public repositories or by reverse‑engineering the firmware image. An attacker with network access to the router can perform the exploit from any connected segment. With an EPSS score of less than 1 %, the likelihood of exploitation is low, yet the guaranteed root access demands immediate remediation. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 20, 2026 at 17:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an updated firmware that removes the hardcoded root credential
  • Change the root password to a unique, strong value if the firmware allows it
  • Disable or lock the root account if the firmware supports it
  • Segment the network to limit exposure of the router

Generated by OpenCVE AI on September 20, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Hardcoded Root Password in TOTOLINK X5000R Router Firmware Enables Unauthorized Access

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Hardcoded Root Password in TOTOLINK X5000R Router Firmware

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Hardcoded Root Password in TOTOLINK X5000R Router Firmware
Weaknesses CWE-798

Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink x5000r
Vendors & Products Totolink
Totolink x5000r

Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-16T16:37:46.669Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-37152

cve-icon Vulnrichment

Updated: 2026-09-16T16:37:34.439Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:08.533

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-37152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:00:14Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials