Totolink X6000R Firmware vulnerabilities
57 known vulnerabilities affecting totolink/x6000r_firmware.
Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL47HIGH6MEDIUM4
Vulnerabilities
Page 1 of 3
CVE-2026-4611HIGHCVSS 8.6v9.4.0cu.1360_b20241207v9.4.0cu.1498_b202508262026-03-23
CVE-2026-4611 [HIGH] CWE-77 CVE-2026-4611: A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by
A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection. The attack may be launched remotely.
nvd
CVE-2025-70328HIGHCVSS 8.8v9.4.0cu.1498_b202508262026-02-23
CVE-2025-70328 [HIGH] CWE-78 CVE-2025-70328: TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyn
TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_40C404 and passed to a date -s shell command through CsteSystem. While the first two tokens of the input are validated, the remainder of the string is not
nvd
CVE-2025-11005CRITICALCVSS 9.3≤ 9.4.0cu.1360_b202412072025-09-25
CVE-2025-11005 [CRITICAL] CWE-78 CVE-2025-11005: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.
nvd
CVE-2025-52906CRITICALCVSS 9.3≤ 9.4.0cu.1360_b202412072025-09-24
CVE-2025-52906 [CRITICAL] CWE-78 CVE-2025-52906: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
nvd
CVE-2025-52907HIGHCVSS 7.3≤ 9.4.0cu.1360_b202412072025-09-24
CVE-2025-52907 [HIGH] CWE-20 CVE-2025-52907: Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulati
Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
nvd
CVE-2025-52905HIGHCVSS 7.0≤ 9.4.0cu.1360_b202412072025-09-23
CVE-2025-52905 [HIGH] CWE-20 CVE-2025-52905: Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R
Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
nvd
CVE-2025-52053CRITICALCVSS 9.8v9.4.0cu.1360_b202412072025-09-15
CVE-2025-52053 [CRITICAL] CWE-77 CVE-2025-52053: TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in th
TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-52284MEDIUMCVSS 6.5v9.4.0cu.1360_b202412072025-07-29
CVE-2025-52284 [MEDIUM] CWE-77 CVE-2025-52284: Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in th
Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-25524MEDIUMCVSS 5.1v9.4.0cu.652_b202301162025-02-11
CVE-2025-25524 [MEDIUM] CWE-120 CVE-2025-25524: Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of l
Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
nvd
CVE-2024-52723CRITICALCVSS 9.8v9.4.0cu.1041_b202402242024-11-22
CVE-2024-52723 [CRITICAL] CWE-78 CVE-2024-52723: In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used with
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
nvd
CVE-2024-7907MEDIUMCVSS 5.3v9.4.0cu.852_b202307192024-08-18
CVE-2024-7907 [MEDIUM] CWE-77 CVE-2024-7907: A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_202
A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument rtLogServer leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be u
nvd
CVE-2024-2353HIGHCVSS 8.8v9.4.0cu.852_b202307192024-03-10
CVE-2024-2353 [HIGH] CWE-78 CVE-2024-2353: A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_202
A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation of the argument ip leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the
nvd
CVE-2024-1781CRITICALCVSS 9.8v9.4.0cu.852_b202307192024-02-23
CVE-2024-1781 [MEDIUM] CWE-77 CVE-2024-1781: A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as criti
A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The identifier VDB-254573 was assigned
nvd
CVE-2024-1661MEDIUMCVSS 5.5v9.4.0cu.852_b202307192024-02-20
CVE-2024-1661 [LOW] CWE-798 CVE-2024-1661: A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affect
A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerability is an unknown functionality of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to b
nvd
CVE-2023-52039CRITICALCVSS 9.8v9.4.0cu.852_b202307192024-01-24
CVE-2023-52039 [CRITICAL] CWE-77 CVE-2023-52039: An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary comm
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.
nvd
CVE-2023-52040CRITICALCVSS 9.8v9.4.0cu.852_b202307192024-01-24
CVE-2023-52040 [CRITICAL] CWE-77 CVE-2023-52040: An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary comm
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.
nvd
CVE-2023-52038CRITICALCVSS 9.8v9.4.0cu.852_b202307192024-01-24
CVE-2023-52038 [CRITICAL] CWE-77 CVE-2023-52038: An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary comm
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.
nvd
CVE-2023-52042CRITICALCVSS 9.8v9.4.0cu.852_b202307192024-01-16
CVE-2023-52042 [CRITICAL] CWE-77 CVE-2023-52042: An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attacker
An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.
nvd
CVE-2023-52041CRITICALCVSS 9.8v9.4.0cu.852_b202307192024-01-16
CVE-2023-52041 [CRITICAL] CVE-2023-52041: An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code
An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd program.
nvd
CVE-2023-50651CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-12-30
CVE-2023-50651 [CRITICAL] CWE-78 CVE-2023-50651: TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vu
TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
nvd
1 / 3Next →