PT-2025-50325 · X5000R · X5000R

Published

2025-12-10

·

Updated

2025-12-10

·

CVE-2025-13184

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions X5000R versions prior to V9.1.0u.6369 B20230113
Description The device allows unauthenticated Telnet access through the cstecgi.cgi interface, bypassing authentication. This allows for unauthenticated root login with a blank password on a factory reset device. Successful exploitation results in arbitrary command execution.
Recommendations Apply updates to versions V9.1.0u.6369 B20230113 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13184

Affected Products

X5000R