cbcvebase.
CVE-2025-52906
published 2025-09-24

CVE-2025-52906: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This…

critical9.3CVSS 4.0
AVNACLATNPRNUINVCLVIHVALSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSNAUYRUVXREXUX
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

Affected

2 ranges
VendorProductVersion rangeFixed in
totolinkx6000r<= V9.4.0cu.1360_B20241207
totolinkx6000r_firmware<= 9.4.0cu.1360_b20241207