← Vulnerability feed

Vulnerability record · CVE-2025-52906 · published 24 September 2025

CVE-2025-52906: Totolink x6000r firmware os command injection vulnerability

TTotolink · X6000r Firmware

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

9.3 CVSS 4.0 Critical EPSS 13% · top 3.8% CWE-78 · OS command injection
9.3CVSS 4.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-52906 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-52053Totolink x6000r firmware command injection vulnerabilityTOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter…EPSS 4.4%9.8CVE-2024-52723Totolink x6000r firmware os command injection vulnerabilityIn TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can a…EPSS 1.0%9.8CVE-2024-1781Totolink x6000r firmware command injection vulnerabilityA vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg…EPSS 15%9.8CVE-2023-52038Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.EPSS 0.77%9.8CVE-2023-52039Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.EPSS 0.77%9.8CVE-2023-52040Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.EPSS 0.85%9.8CVE-2023-52042Totolink x6000r firmware command injection vulnerabilityAn issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parame…EPSS 0.95%9.8CVE-2023-52041Totolink x6000r firmware vulnerabilityAn issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd progra…EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2025-52906), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.