VendorsTOTOLINKx6000rall versions
Vulnerabilities

TOTOLINK X6000R

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2023-46485
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.
Published 2023-10-31 · Modified
9.8EPSS 0.012
CVE-2023-46484
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.
Published 2023-10-31 · Modified
9.8EPSS 0.012
CVE-2024-52723
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
Published 2024-11-22 · Modified
9.8EPSS 0.010
CVE-2023-52042
An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.
Published 2024-01-16 · Modified
9.8EPSS 0.009
CVE-2023-52041
An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd program.
Published 2024-01-16 · Modified
9.8EPSS 0.009
CVE-2023-52040
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.
Published 2024-01-24 · Modified
9.8EPSS 0.009
CVE-2023-52039
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.
Published 2024-01-24 · Modified
9.8EPSS 0.008
CVE-2023-52038
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.
Published 2024-01-24 · Modified
9.8EPSS 0.008
CVE-2024-2353
Totolink X6000R shttpd cstecgi.cgi setDiagnosisCfg os command injection
Published 2024-03-10 · Analyzed
9.0EPSS 0.040
CVE-2026-4611
TOTOLINK X6000R shttpd setLanCfg privilege escalation
Published 2026-03-23 · Analyzed
8.8EPSS 0.053
CVE-2025-70328
TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_40C404 and passed to a date -s shell command through CsteSystem. While the first two tokens of the input are validated, the remainder of the string is not sanitized, allowing authenticated attackers to execute arbitrary shell commands via shell metacharacters.
Published 2026-02-23 · Analyzed
8.8EPSS 0.018
CVE-2025-52907
TOTOLINK X6000R Security Bypass Vulnerability
Published 2025-09-24 · Analyzed
8.8EPSS 0.008
CVE-2025-52905
TOTOLINK X6000R Argument Injection Vulnerability
Published 2025-09-23 · Analyzed
7.5EPSS 0.081
CVE-2023-46978
TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords without authentication.
Published 2023-10-31 · Modified
7.5EPSS 0.005
CVE-2025-52284
Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
Published 2025-07-29 · Modified
6.5EPSS 0.023
CVE-2025-25524
Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
Published 2025-02-11 · Analyzed
5.1EPSS 0.002
← Prev2 / 2