PT-2025-39313 · Totolink · Totolink X6000R

Published

2025-09-24

·

Updated

2025-10-01

·

CVE-2025-52907

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK X6000R versions through V9.4.0cu.1360 B20241207
Description The software contains an improper input validation issue that can lead to command injection and file manipulation. The vulnerability exists due to insufficient validation of user-supplied input. This allows an attacker to inject arbitrary commands and manipulate files on the system. There is no information about the number of potentially affected devices or any real-world incidents where this issue was exploited.
Recommendations Update TOTOLINK X6000R to a version later than V9.4.0cu.1360 B20241207.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-12684
CVE-2025-52907

Affected Products

Totolink X6000R