PT-2026-21552 · Totolink · Totolink X6000R

Published

2025-10-22

·

Updated

2026-02-28

·

CVE-2025-70328

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK X6000R version 9.4.0cu.1498 B20250826
Description The software contains an OS command injection issue in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host time parameter is processed by the sub 40C404 function and passed to a date -s shell command through CsteSystem. While initial tokens of the input are validated, the remaining input is not sanitized, potentially allowing authenticated attackers to execute arbitrary shell commands using shell metacharacters.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the NTPSyncWithHost handler.

Exploit

Fix

OS Command Injection

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-02542
CVE-2025-70328

Affected Products

Totolink X6000R