CVE-2025-70328

TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_40C404 and passed to a date -s shell command through CsteSystem. While the first two tokens of the input are validated, the remainder of the string is not sanitized, allowing authenticated attackers to execute arbitrary shell commands via shell metacharacters.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.1498_b20250826:*:*:*:*:*:*:*
cpe:2.3:h:totolink:x6000r:-:*:*:*:*:*:*:*

History

26 Feb 2026, 03:06

Type Values Removed Values Added
CPE cpe:2.3:h:totolink:x6000r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.1498_b20250826:*:*:*:*:*:*:*
First Time Totolink
Totolink x6000r
Totolink x6000r Firmware
CWE CWE-78
References () https://github.com/neighborhood-H/0-DAY/blob/main/Toto-link/X6000R/NTPSyncWihtHost/report.md - () https://github.com/neighborhood-H/0-DAY/blob/main/Toto-link/X6000R/NTPSyncWihtHost/report.md - Exploit, Third Party Advisory
References () https://www.notion.so/TOTOLINK-X6000R-NTPSyncWithHost-2d170566ca7f803a8096c1b31b2ed42f?source=copy_link - () https://www.notion.so/TOTOLINK-X6000R-NTPSyncWithHost-2d170566ca7f803a8096c1b31b2ed42f?source=copy_link - Exploit, Third Party Advisory

25 Feb 2026, 15:20

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-94
Summary
  • (es) TOTOLINK X6000R v9.4.0cu.1498_B20250826 contiene una vulnerabilidad de inyección de comandos del sistema operativo en el gestor NTPSyncWithHost del ejecutable /usr/sbin/shttpd. El parámetro host_time se recupera a través de sub_40C404 y se pasa a un comando de shell date -s a través de CsteSystem. Aunque los dos primeros tokens de la entrada son validados, el resto de la cadena no se sanea, permitiendo a atacantes autenticados ejecutar comandos de shell arbitrarios a través de metacaracteres de shell.

23 Feb 2026, 21:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 21:19

Updated : 2026-02-26 03:06


NVD link : CVE-2025-70328

Mitre link : CVE-2025-70328

CVE.ORG link : CVE-2025-70328


JSON object : View

Products Affected

totolink

  • x6000r_firmware
  • x6000r
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')