Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.
The vulnerability results from improper neutralization of special characters passed to operating system commands (CWE-78). An attacker can supply properly crafted input data containing malicious sequences, which are then interpreted and executed by the system shell without proper verification. The attack does not require authentication or user interaction and can be conducted remotely over the network.
An attacker can gain unauthorized access to the device's operating system, read sensitive configuration data, disrupt router operation, and potentially use the compromised device for further attacks on internal networks.
The TOTOLINK X6000R router firmware should be updated to a version newer than V9.4.0cu.1458_B20250708 when released by the manufacturer. Until the patch is applied, it is recommended to restrict access to the device management interface only to trusted hosts and isolate the device from untrusted networks. The patch should be obtained according to the manufacturer's references available at the address specified on the official TOTOLINK website.
TOTOLINK X6000R in all firmware versions up to and including V9.4.0cu.1458_B20250708.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XTotolink X6000r
HWTotolinkall versionsTotolink X6000r Firmware
OSTotolink≤ 9.4.0cu.1360_b20241207
Related vulnerabilities
OS Command Injection w firmware routera TOTOLINK X6000R
Command injection w TOTOLINK X6000R – zdalne wykonanie kodu bez uwierzytelnienia
Command injection w TOTOLINK X6000R — zdalne wykonanie poleceń bez uwierzytelnienia
Command Injection w TOTOLINK X6000R — wykonanie dowolnych poleceń
Command injection w TOTOLINK X6000R umożliwia zdalne wykonanie kodu