VendorsTOTOLINKx6000r_firmware9.4.0cu.1360_b20241207
Vulnerabilities

TOTOLINK X6000R Firmware 9.4.0cu.652 B20230116 9.4.0cu.1360_b20241207

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2025-52053
TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
Published 2025-09-15 · Analyzed
9.8EPSS 0.044
CVE-2026-4611
TOTOLINK X6000R shttpd setLanCfg privilege escalation
Published 2026-03-23 · Analyzed
8.8EPSS 0.053
CVE-2025-52284
Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
Published 2025-07-29 · Modified
6.5EPSS 0.023