PT-2026-21552 · Totolink · Totolink X6000R

CVE-2025-70328

·

Publicado

2025-10-22

·

Atualizado

2026-02-28

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK X6000R version 9.4.0cu.1498 B20250826
Description The software contains an OS command injection issue in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host time parameter is processed by the sub 40C404 function and passed to a date -s shell command through CsteSystem. While initial tokens of the input are validated, the remaining input is not sanitized, potentially allowing authenticated attackers to execute arbitrary shell commands using shell metacharacters.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the NTPSyncWithHost handler.

Exploit

Correção

OS Command Injection

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-02542
CVE-2025-70328

Produtos afetados

Totolink X6000R