CVE-2025-13184: Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13184?
CVE-2025-13184 is considered a critical vulnerability due to its potential for remote unauthenticated root access.
How do I fix CVE-2025-13184?
To mitigate CVE-2025-13184, update the X5000R firmware to the latest version that addresses the vulnerability.
What are the potential impacts of CVE-2025-13184?
CVE-2025-13184 allows attackers to execute arbitrary commands and gain full control of the device due to unauthenticated access.
Which devices are affected by CVE-2025-13184?
CVE-2025-13184 specifically affects the X5000R V9.1.0u.6369_B20230113 router and possibly earlier versions with similar implementations.
Is user authentication required for CVE-2025-13184 exploitation?
No, CVE-2025-13184 can be exploited without any user authentication, allowing access to the device with a blank password.