PT-2024-14370 · Totolink · Totolink X6000R

Kee02P

·

Published

2024-01-13

·

Updated

2025-06-17

·

CVE-2023-52041

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK X6000R version 9.4.0cu.852 B20230719
Description An issue in the TOTOLINK X6000R allows attackers to run arbitrary code via the sub 410118 function of the shttpd program.
Recommendations For TOTOLINK X6000R version 9.4.0cu.852 B20230719, consider disabling the sub 410118 function of the shttpd program as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-11317
CVE-2023-52041

Affected Products

Totolink X6000R