PT-2025-37705 · Totolink · Totolink X6000R
W0Rkd4Tt
·
Published
2025-07-30
·
Updated
2025-09-20
·
CVE-2025-52053
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TOTOLINK X6000R version 9.4.0cu.1360 B20241207
Description
The vulnerability resides in the
sub 417D74() function of the TOTOLINK X6000R router's firmware. The issue is due to a lack of data sanitization on the management level when processing the file name parameter. This allows unauthenticated attackers to execute arbitrary commands via a crafted request.Recommendations
TOTOLINK X6000R version 9.4.0cu.1360 B20241207: As a temporary workaround, consider restricting access to the
sub 417D74() function until a patch is available.Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Totolink X6000R