PT-2026-21552 · Totolink · Totolink X6000R
CVE-2025-70328
·
Publicado
2025-10-22
·
Atualizado
2026-02-28
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TOTOLINK X6000R version 9.4.0cu.1498 B20250826
Description
The software contains an OS command injection issue in the NTPSyncWithHost handler of the
/usr/sbin/shttpd executable. The host time parameter is processed by the sub 40C404 function and passed to a date -s shell command through CsteSystem. While initial tokens of the input are validated, the remaining input is not sanitized, potentially allowing authenticated attackers to execute arbitrary shell commands using shell metacharacters.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the NTPSyncWithHost handler.
Exploit
Correção
OS Command Injection
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Totolink X6000R