PT-2025-39310 · Totolink · Totolink X6000R

Published

2025-09-24

·

Updated

2025-11-08

·

CVE-2025-52906

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK X6000R versions through V9.4.0cu.1360 B20241207
Description A flaw exists in TOTOLINK X6000R that allows for OS Command Injection. This occurs due to improper neutralization of special elements used in an OS command. An attacker could potentially execute malicious commands on the system.
Recommendations Update TOTOLINK X6000R to a version later than V9.4.0cu.1360 B20241207.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-52906

Affected Products

Totolink X6000R