CRITICAL🇵🇱 Wersja polska

CVE-2025-52906

CVSS 9.3v4.0pub. 2025-09-24upd. 2025-10-14

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

🤖 AI Analysis
How it works

The firmware of the TOTOLINK X6000R device improperly neutralizes special characters passed to operating system commands (CWE-78). An attacker can craft an appropriate network request containing a malicious payload, which will be passed directly to the system shell interpreter without the required filtering. No authentication or user interaction is required.

Impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary operating system commands with the privileges of the vulnerable service process, which may lead to complete takeover of the device and potentially compromise the security of systems connected to the protected network.

Mitigation & patch

The TOTOLINK X6000R device firmware should be updated to a version newer than V9.4.0cu.1360_B20241207. The update can be downloaded from the manufacturer's website indicated in the references. Until the patch is applied, it is recommended to restrict access to the device management interface exclusively to trusted hosts and isolate the device from untrusted network segments.

Who is affected

TOTOLINK X6000R with firmware version up to and including V9.4.0cu.1360_B20241207.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:X/RE:X/U:X
  • Totolink X6000r

    HW
    Totolink
    all versions
  • Totolink X6000r Firmware

    OS
    Totolink
    ≤ 9.4.0cu.1360_b20241207
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2025-11005CRITICAL9.3PL ✓same product

OS Command Injection w TOTOLINK X6000R — zdalne wykonanie poleceń

CVE-2025-52053CRITICAL9.8PL ✓same product

Command injection w TOTOLINK X6000R – zdalne wykonanie kodu bez uwierzytelnienia

CVE-2024-52723CRITICAL9.8PL ✓same product

Command injection w TOTOLINK X6000R — zdalne wykonanie poleceń bez uwierzytelnienia

CVE-2023-52038CRITICAL9.8PL ✓same product

Command Injection w TOTOLINK X6000R — wykonanie dowolnych poleceń

CVE-2023-52039CRITICAL9.8PL ✓same product

Command injection w TOTOLINK X6000R umożliwia zdalne wykonanie kodu