PT-2025-37705 · Totolink · Totolink X6000R

W0Rkd4Tt

·

Published

2025-07-30

·

Updated

2025-09-20

·

CVE-2025-52053

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK X6000R version 9.4.0cu.1360 B20241207
Description The vulnerability resides in the sub 417D74() function of the TOTOLINK X6000R router's firmware. The issue is due to a lack of data sanitization on the management level when processing the file name parameter. This allows unauthenticated attackers to execute arbitrary commands via a crafted request.
Recommendations TOTOLINK X6000R version 9.4.0cu.1360 B20241207: As a temporary workaround, consider restricting access to the sub 417D74() function until a patch is available.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-11310
CVE-2025-52053

Affected Products

Totolink X6000R