CVE-2025-25604: Totolink x5000r Firmware

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.

Affected products

  • Totolink x5000r Firmware: version 9.1.0u.6369_b20230113 only

Published 2025-02-21. Last modified 2026-06-17.