TOTOLINK X6000R OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the TOTOLINK X6000R router, specifically in versions through V9.4.0cu.1458_B20250708. This vulnerability allows an unauthenticated attacker to execute arbitrary operating system commands on the device. The issue arises from improper sanitization of user-supplied input in the 'setWiFiAclRules' function, where shell metacharacters can be injected and executed as commands on the underlying OS.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device.

Remediation

TOTOLINK has released a patched firmware version. Users can download the latest firmware from the TOTOLINK Download Center.

Added: Sep 25, 2025, 9:29 PM
Updated: Sep 25, 2025, 9:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
7.8
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.