VendorsTOTOLINKx6000r_firmware9.4.0cu.652_b20230116
Vulnerabilities

TOTOLINK X6000R Firmware 9.4.0cu.652 B20230116 9.4.0cu.652_b20230116

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2023-46424
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4 function.
Published 2023-10-25 · Modified
9.8EPSS 0.019
CVE-2023-46423
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094 function.
Published 2023-10-25 · Modified
9.8EPSS 0.019
CVE-2023-46422
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function.
Published 2023-10-25 · Modified
9.8EPSS 0.019
CVE-2023-46421
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function.
Published 2023-10-25 · Modified
9.8EPSS 0.019
CVE-2023-46420
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function.
Published 2023-10-25 · Modified
9.8EPSS 0.019
CVE-2023-46419
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function.
Published 2023-10-25 · Modified
9.8EPSS 0.019
CVE-2023-46418
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function.
Published 2023-10-25 · Modified
9.8EPSS 0.019
CVE-2023-46417
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.
Published 2023-10-25 · Modified
9.8EPSS 0.019
CVE-2023-46414
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.
Published 2023-10-25 · Modified
9.8EPSS 0.019
CVE-2023-46415
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.
Published 2023-10-25 · Modified
9.8EPSS 0.019
CVE-2023-46416
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function.
Published 2023-10-25 · Modified
9.8EPSS 0.019
CVE-2023-43454
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName parameter of the switchOpMode component.
Published 2023-12-01 · Modified
9.8EPSS 0.015
CVE-2023-43455
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command parameter of the setting/setTracerouteCfg component.
Published 2023-12-01 · Modified
9.8EPSS 0.015
CVE-2023-43453
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.
Published 2023-12-01 · Modified
9.8EPSS 0.015
CVE-2023-46413
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function.
Published 2023-10-25 · Modified
9.8EPSS 0.014
CVE-2023-46412
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function.
Published 2023-10-25 · Modified
9.8EPSS 0.014
CVE-2023-46411
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.
Published 2023-10-25 · Modified
9.8EPSS 0.014
CVE-2023-46410
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 function.
Published 2023-10-25 · Modified
9.8EPSS 0.014
CVE-2023-46409
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.
Published 2023-10-25 · Modified
9.8EPSS 0.014
CVE-2023-46408
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 function.
Published 2023-10-25 · Modified
9.8EPSS 0.014
CVE-2025-25524
Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
Published 2025-02-11 · Analyzed
5.1EPSS 0.002