Skip to main content

Vendor/product archive

totolink / x6000r_firmware CVEs

Beta · best-effort

57 CVEs tagged to totolink / x6000r_firmware46 Critical, 6 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2026-4611

Published Mar 23, 2026

A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a…

CVSS 8.6 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-11005

Published Sep 25, 2025

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R:…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-52907

Published Sep 24, 2025

Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

CVSS 7.3 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-52906

Published Sep 24, 2025

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R:…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-52053

Published Sep 15, 2025

TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter. This vulnerability allows un…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
25.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-52284

Published Jul 29, 2025

Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This vulnerability allows unauthent…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-25524

Published Feb 11, 2025

Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules.…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-52723

Published Nov 22, 2024

In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-7907

Published Aug 18, 2024

A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecg…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2353

Published Mar 10, 2024

A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cst…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1781

Published Feb 23, 2024

A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-1661

Published Feb 20, 2024

A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerability is an unknown functionality of the file /etc/shadow. T…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-52041

Published Jan 16, 2024

An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd program.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-48800

Published Dec 4, 2023

In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-48801

Published Dec 1, 2023

In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-43455

Published Dec 1, 2023

An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command parameter of the setting/setTracer…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-43454

Published Dec 1, 2023

An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName parameter of the switchOpMode com…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 57 CVEsPage 1 of 3