Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
The firmware of the TOTOLINK X6000R device improperly neutralizes special characters passed to operating system commands (CWE-78). An attacker can craft an appropriate network request containing a malicious payload, which will be passed directly to the system shell interpreter without the required filtering. No authentication or user interaction is required.
Successful exploitation of this vulnerability allows an attacker to execute arbitrary operating system commands with the privileges of the vulnerable service process, which may lead to complete takeover of the device and potentially compromise the security of systems connected to the protected network.
The TOTOLINK X6000R device firmware should be updated to a version newer than V9.4.0cu.1360_B20241207. The update can be downloaded from the manufacturer's website indicated in the references. Until the patch is applied, it is recommended to restrict access to the device management interface exclusively to trusted hosts and isolate the device from untrusted network segments.
TOTOLINK X6000R with firmware version up to and including V9.4.0cu.1360_B20241207.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:X/RE:X/U:XTotolink X6000r
HWTotolinkall versionsTotolink X6000r Firmware
OSTotolink≤ 9.4.0cu.1360_b20241207
Related vulnerabilities
OS Command Injection w TOTOLINK X6000R — zdalne wykonanie poleceń
Command injection w TOTOLINK X6000R – zdalne wykonanie kodu bez uwierzytelnienia
Command injection w TOTOLINK X6000R — zdalne wykonanie poleceń bez uwierzytelnienia
Command Injection w TOTOLINK X6000R — wykonanie dowolnych poleceń
Command injection w TOTOLINK X6000R umożliwia zdalne wykonanie kodu