TOTOLINK A6000R Command Injection Vulnerability in Password Change Function

Vulnerability

A command injection vulnerability has been identified in the TOTOLINK A6000R router, specifically in version 1.0.1-B20201211.2000. The issue arises in the action_passwd function, where the newpasswd parameter is improperly sanitized, allowing attackers to inject and execute arbitrary commands.

Impact

Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the device with the same privileges as the application or service processing the request.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
10.0
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.