TOTOLINK X6000R OS Command Injection Vulnerability

Vulnerability

A vulnerability allowing OS command injection has been identified in the TOTOLINK X6000R router, affecting versions through V9.4.0cu.1498_B20250826. This vulnerability arises from improper neutralization of special elements used in OS commands, allowing attackers to execute arbitrary commands on the operating system.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device.

Added: Jan 30, 2026, 9:20 PM
Updated: Jan 30, 2026, 9:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
6.6
remediation
0.0
relevance
2.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.