cbcvebase.
CVE-2025-11005
published 2025-09-25

CVE-2025-11005: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This…

critical9.3CVSS 4.0
AVNACLATNPRNUINVCHVILVAHSCHSILSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.

Affected

2 ranges
VendorProductVersion rangeFixed in
totolinkx6000r<= V9.4.0cu.1458_B20250708
totolinkx6000r_firmware<= 9.4.0cu.1360_b20241207