CVE-2025-52906

TOTOLINK X6000R Command Injection Vulnerability

Severity
Critical 9.3
CVSS 4.0
Exploited
Not listed
EPSS
0.132
96.0th percentile
Discovered by
Third party
Published by the vendor
Published
Sep 24, 2025
Assigned by palo_alto

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • TOTOLINK · X6000R