CRITICAL🇵🇱 Wersja polska

CVE-2025-11005

CVSS 9.3v4.0pub. 2025-09-25upd. 2025-10-16

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.

🤖 AI Analysis
How it works

The vulnerability results from improper neutralization of special characters passed to operating system commands (CWE-78). An attacker can supply properly crafted input data containing malicious sequences, which are then interpreted and executed by the system shell without proper verification. The attack does not require authentication or user interaction and can be conducted remotely over the network.

Impact

An attacker can gain unauthorized access to the device's operating system, read sensitive configuration data, disrupt router operation, and potentially use the compromised device for further attacks on internal networks.

Mitigation & patch

The TOTOLINK X6000R router firmware should be updated to a version newer than V9.4.0cu.1458_B20250708 when released by the manufacturer. Until the patch is applied, it is recommended to restrict access to the device management interface only to trusted hosts and isolate the device from untrusted networks. The patch should be obtained according to the manufacturer's references available at the address specified on the official TOTOLINK website.

Who is affected

TOTOLINK X6000R in all firmware versions up to and including V9.4.0cu.1458_B20250708.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Totolink X6000r

    HW
    Totolink
    all versions
  • Totolink X6000r Firmware

    OS
    Totolink
    ≤ 9.4.0cu.1360_b20241207
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2025-52906CRITICAL9.3PL ✓same product

OS Command Injection w firmware routera TOTOLINK X6000R

CVE-2025-52053CRITICAL9.8PL ✓same product

Command injection w TOTOLINK X6000R – zdalne wykonanie kodu bez uwierzytelnienia

CVE-2024-52723CRITICAL9.8PL ✓same product

Command injection w TOTOLINK X6000R — zdalne wykonanie poleceń bez uwierzytelnienia

CVE-2023-52038CRITICAL9.8PL ✓same product

Command Injection w TOTOLINK X6000R — wykonanie dowolnych poleceń

CVE-2023-52039CRITICAL9.8PL ✓same product

Command injection w TOTOLINK X6000R umożliwia zdalne wykonanie kodu