TOTOLINK X6000R
cpe:2.3:h:totolink:x6000r:*:*:*:*:*:*:*, +1 more
- <= V9.4.0cu.1360_B20241207
A command injection vulnerability has been identified in the TOTOLINK X6000R router, affecting firmware versions through V9.4.0cu.1360_B20241207. This vulnerability allows an unauthenticated attacker to execute arbitrary operating system commands on the device. The issue arises from improper sanitization of the 'agentName' parameter in the 'setEasyMeshAgentCfg' function, which is used to configure EasyMesh agent settings. Attackers can exploit this by injecting shell metacharacters into the 'agentName' value, bypassing input validation and executing malicious payloads as separate commands on the operating system.
Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device.
TOTOLINK has released a patched firmware version. The latest version can be downloaded from the TOTOLINK Download Center.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.