← Vulnerability feed

Vulnerability record · CVE-2026-4611 · published 23 March 2026

CVE-2026-4611: Totolink x6000r firmware command injection vulnerability

TTotolink · X6000r Firmware

A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection. The attack may be launched remotely.

8.6 CVSS 4.0 High EPSS 5.3% · top 7.8% CWE-77 · Command injectionCWE-78 · OS command injection
8.6CVSS 4.0 base score, v2 8.3
5.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection. The attack may be launched remotely.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://vuldb.com/?ctiid.352475 Permissions RequiredVDB Entry
https://vuldb.com/?id.352475 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.775642 Third Party AdvisoryVDB Entry
https://www.totolink.net/ Product

Track CVE-2026-4611 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-52053Totolink x6000r firmware command injection vulnerabilityTOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter…EPSS 4.4%9.8CVE-2024-52723Totolink x6000r firmware os command injection vulnerabilityIn TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can a…EPSS 1.0%9.8CVE-2024-1781Totolink x6000r firmware command injection vulnerabilityA vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg…EPSS 15%9.8CVE-2023-52038Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.EPSS 0.77%9.8CVE-2023-52039Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.EPSS 0.77%9.8CVE-2023-52040Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.EPSS 0.85%9.8CVE-2023-52042Totolink x6000r firmware command injection vulnerabilityAn issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parame…EPSS 0.95%9.8CVE-2023-52041Totolink x6000r firmware vulnerabilityAn issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd progra…EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2026-4611), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.