CVE-2026-1723

TOTOLINK X6000R Unauthenticated Command Injection Vulnerability

Severity
Critical 9.2
CVSS 4.0
Exploited
Not listed
EPSS
0.009
56.2th percentile
Discovered by
Third party
Published by the vendor
Published
Jan 30, 2026
Assigned by palo_alto

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1498_B20250826.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • TOTOLINK · X6000R