cbcvebase.

Totolink X6000R Firmware vulnerabilities

57 known vulnerabilities affecting totolink/x6000r_firmware.

Total CVEs
57
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL48HIGH6MEDIUM3

Vulnerabilities

Page 1 of 3
CVE-2024-1781P1CRITICALCVSS 9.8ExploitedPoCv9.4.0cu.852_b202307192024-02-23
CVE-2024-1781 [CRITICAL] CWE-77 CVE-2024-1781: A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as criti A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The identifier VDB-254573 was assigne
nvd
CVE-2024-2353P1HIGHCVSS 8.8Exploitedv9.4.0cu.852_b202307192024-03-10
CVE-2024-2353 [HIGH] CWE-78 CVE-2024-2353: A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_202 A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation of the argument ip leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the
nvd
CVE-2025-52906P2CRITICALCVSS 9.8≤ 9.4.0cu.1360_b202412072025-09-24
CVE-2025-52906 [CRITICAL] CWE-78 CVE-2025-52906: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
nvd
CVE-2025-52053P2CRITICALCVSS 9.8v9.4.0cu.1360_b202412072025-09-15
CVE-2025-52053 [CRITICAL] CWE-77 CVE-2025-52053: TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in th TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2024-7907P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192024-08-18
CVE-2024-7907 [CRITICAL] CWE-77 CVE-2024-7907: A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_202 A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument rtLogServer leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be
nvd
CVE-2025-11005P2CRITICALCVSS 9.8≤ 9.4.0cu.1360_b202412072025-09-25
CVE-2025-11005 [CRITICAL] CWE-78 CVE-2025-11005: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.
nvd
CVE-2026-4611P2HIGHCVSS 8.8v9.4.0cu.1360_b20241207v9.4.0cu.1498_b202508262026-03-23
CVE-2026-4611 [HIGH] CWE-77 CVE-2026-4611: A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection. The attack may be launched remotely.
nvd
CVE-2025-70328P2HIGHCVSS 8.8v9.4.0cu.1498_b202508262026-02-23
CVE-2025-70328 [HIGH] CWE-78 CVE-2025-70328: TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyn TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_40C404 and passed to a date -s shell command through CsteSystem. While the first two tokens of the input are validated, the remainder of the string is not
nvd
CVE-2023-46979P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-10-31
CVE-2023-46979 [CRITICAL] CWE-77 CVE-2023-46979: TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability v TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.
nvd
CVE-2023-48803P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-11-30
CVE-2023-48803 [CRITICAL] CWE-78 CVE-2023-48803: In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
nvd
CVE-2023-48811P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-11-30
CVE-2023-48811 [CRITICAL] CWE-78 CVE-2023-48811: In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.
nvd
CVE-2023-48808P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-11-30
CVE-2023-48808 [CRITICAL] CWE-78 CVE-2023-48808: In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
nvd
CVE-2023-48807P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-11-30
CVE-2023-48807 [CRITICAL] CWE-78 CVE-2023-48807: In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
nvd
CVE-2023-48805P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-11-30
CVE-2023-48805 [CRITICAL] CWE-78 CVE-2023-48805: In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
nvd
CVE-2023-48804P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-11-30
CVE-2023-48804 [CRITICAL] CWE-78 CVE-2023-48804: In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
nvd
CVE-2023-48802P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-11-30
CVE-2023-48802 [CRITICAL] CWE-78 CVE-2023-48802: In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
nvd
CVE-2023-48806P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-11-30
CVE-2023-48806 [CRITICAL] CWE-78 CVE-2023-48806: In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
nvd
CVE-2023-48812P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-11-30
CVE-2023-48812 [CRITICAL] CWE-78 CVE-2023-48812: In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from t In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.
nvd
CVE-2023-48810P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-11-30
CVE-2023-48810 [CRITICAL] CWE-78 CVE-2023-48810: In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
nvd
CVE-2024-52723P2CRITICALCVSS 9.8v9.4.0cu.1041_b202402242024-11-22
CVE-2024-52723 [CRITICAL] CWE-78 CVE-2024-52723: In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used with In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
nvd
Totolink X6000R Firmware vulnerabilities | cvebase