CVE-2026-1723
TOTOLINK X6000R Unauthenticated Command Injection Vulnerability
Severity
Critical 9.2
CVSS 4.0
Exploited
Not listed
EPSS
0.010
60.0th percentile
Discovered by
Third party
Vendor-published field
Published
Jan 30, 2026
Assigned by palo_alto
Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1498_B20250826.
Weakness: CWE-78
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported products (1)
- TOTOLINK · X6000R