CVE-2025-52905

TOTOLINK X6000R Argument Injection Vulnerability

Severity
High 7
CVSS 4.0
Exploited
Not listed
EPSS
0.078
94.0th percentile
Discovered by
Third party
Published by the vendor
Published
Sep 23, 2025
Assigned by palo_alto

Description

Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • TOTOLINK · X6000R