CVE-2026-1723
TOTOLINK X6000R Unauthenticated Command Injection Vulnerability
Severity
Critical 9.2
CVSS 4.0
Exploited
Not listed
EPSS
0.009
56.2th percentile
Discovered by
Third party
Published by the vendor
Published
Jan 30, 2026
Assigned by palo_alto
Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1498_B20250826.
Weakness: CWE-78
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported affected versions (1)
- TOTOLINK · X6000R