CVE-2025-52906
TOTOLINK X6000R Command Injection Vulnerability
Severity
Critical 9.3
CVSS 4.0
Exploited
Not listed
EPSS
0.132
96.0th percentile
Discovered by
Third party
Published by the vendor
Published
Sep 24, 2025
Assigned by palo_alto
Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
Weakness: CWE-78
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported affected versions (1)
- TOTOLINK · X6000R