CVE-2025-52906

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:x6000r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:x6000r:-:*:*:*:*:*:*:*

History

17 Jun 2026, 09:37

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de Neutralización Inadecuada de Elementos Especiales utilizados en un Comando de SO ('Inyección de Comandos de SO') en TOTOLINK X6000R permite la inyección de comandos de SO. Este problema afecta a X6000R: hasta V9.4.0cu.1360_B20241207.

14 Oct 2025, 19:45

Type Values Removed Values Added
First Time Totolink x6000r Firmware
Totolink
Totolink x6000r
References () https://github.com/PaloAltoNetworks/u42-vulnerability-disclosures/blob/main/2025/PANW-2025-0002/PANW-2025-0002.md - () https://github.com/PaloAltoNetworks/u42-vulnerability-disclosures/blob/main/2025/PANW-2025-0002/PANW-2025-0002.md - Third Party Advisory
References () https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/247/ids/36.html - () https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/247/ids/36.html - Product
CPE cpe:2.3:h:totolink:x6000r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:x6000r_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

24 Sep 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-24 18:15

Updated : 2026-06-17 09:37


NVD link : CVE-2025-52906

Mitre link : CVE-2025-52906

CVE.ORG link : CVE-2025-52906


JSON object : View

Products Affected

totolink

  • x6000r
  • x6000r_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')