CVE-2023-33485: Totolink x5000r Firmware

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function.

Affected products

  • Totolink x5000r Firmware: version 9.1.0u.6118_b20201102 only; version 9.1.0u.6369_b20230113 only

Published 2023-05-31. Last modified 2026-06-17.