Hardcoded Password Vulnerability in TOTOLINK X5000R Router
CVE-2026-37152

9.8CRITICAL

Key Information:

Vendor

TOTOLINK

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-37152?

A significant security flaw has been discovered in the TOTOLINK X5000R router, where a hardcoded password for root access is embedded within the device's firmware. This vulnerability exposes devices to unauthorized access, enabling potential attackers to compromise network integrity and control over the device. Users are strongly advised to evaluate their security posture and update their devices as recommended by security advisories.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.