CVE-2025-52907

TOTOLINK X6000R Security Bypass Vulnerability

Severity
High 7.3
CVSS 4.0
Exploited
Not listed
EPSS
0.009
55.3th percentile
Discovered by
Third party
Published by the vendor
Published
Sep 24, 2025
Assigned by palo_alto

Description

Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • TOTOLINK · X6000R