CVE-2025-52906

TOTOLINK X6000R Command Injection Vulnerability

Severity
Critical 9.3
CVSS 4.0
Exploited
Not listed
EPSS
0.128
96.1th percentile
Discovered by
Third party
Vendor-published field
Published
Sep 24, 2025
Assigned by palo_alto

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported products (1)
  • TOTOLINK · X6000R

Something wrong here?