Totolink
Totolink X6000r Firmware: vulnerabilidades y CVE
Totolink X6000r Firmware tiene 57 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 47 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE57
Últimos 12 meses2
Críticas47
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-4611 | Alta (8.6) | 5.3% | — | 23 mar 2026 | A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname… |
| CVE-2025-70328 | Alta (8.8) | 1.8% | — | 23 feb 2026 | TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_40C404 and passed to… |
| CVE-2025-11005 | Crítica (9.3) | 1.3% | — | 25 sept 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708. |
| CVE-2025-52907 | Alta (7.3) | 0.85% | — | 24 sept 2025 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207. |
| CVE-2025-52906 | Crítica (9.3) | 13% | — | 24 sept 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207. |
| CVE-2025-52905 | Alta (7) | 8.1% | — | 23 sept 2025 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207. |
| CVE-2025-52053 | Crítica (9.8) | 4.4% | — | 15 sept 2025 | TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter. This vulnerability allows unauthenticated attackers to execute… |
| CVE-2025-52284 | Media (6.5) | 2.3% | — | 29 jul 2025 | Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This vulnerability allows unauthenticated attackers to execute arbitrary… |
| CVE-2025-25524 | Media (5.1) | 0.18% | — | 11 feb 2025 | Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this… |
| CVE-2024-52723 | Crítica (9.8) | 1.0% | — | 22 nov 2024 | In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload. |
| CVE-2024-7907 | Media (5.3) | 6.2% | — | 18 ago 2024 | A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument… |
| CVE-2024-2353 | Alta (8.8) | 4.0% | — | 10 mar 2024 | A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The… |
| CVE-2024-1781 | Crítica (9.8) | 15% | — | 23 feb 2024 | A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The… |
| CVE-2024-1661 | Media (5.5) | 0.32% | — | 20 feb 2024 | A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerability is an unknown functionality of the file /etc/shadow. The manipulation leads to hard-coded… |
| CVE-2023-52040 | Crítica (9.8) | 0.85% | — | 24 ene 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function. |
| CVE-2023-52039 | Crítica (9.8) | 0.77% | — | 24 ene 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function. |
| CVE-2023-52038 | Crítica (9.8) | 0.77% | — | 24 ene 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function. |
| CVE-2023-52042 | Crítica (9.8) | 0.95% | — | 16 ene 2024 | An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter. |
| CVE-2023-52041 | Crítica (9.8) | 0.86% | — | 16 ene 2024 | An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd program. |
| CVE-2023-50651 | Crítica (9.8) | 2.8% | — | 30 dic 2023 | TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi. |
| CVE-2023-48800 | Crítica (9.8) | 1.6% | — | 4 dic 2023 | In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function,… |
| CVE-2023-48799 | Crítica (9.8) | 1.4% | — | 4 dic 2023 | TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution. |
| CVE-2023-48801 | Crítica (9.8) | 1.7% | — | 1 dic 2023 | In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function,… |
| CVE-2023-43455 | Crítica (9.8) | 1.5% | — | 1 dic 2023 | An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command parameter of the setting/setTracerouteCfg component. |
| CVE-2023-43454 | Crítica (9.8) | 1.5% | — | 1 dic 2023 | An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName parameter of the switchOpMode component. |
| CVE-2023-43453 | Crítica (9.8) | 1.5% | — | 1 dic 2023 | An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component. |
| CVE-2023-48812 | Crítica (9.8) | 1.5% | — | 30 nov 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution… |
| CVE-2023-48811 | Crítica (9.8) | 1.5% | — | 30 nov 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command… |
| CVE-2023-48810 | Crítica (9.8) | 1.5% | — | 30 nov 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution… |
| CVE-2023-48808 | Crítica (9.8) | 1.5% | — | 30 nov 2023 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.