Home/Product/totolink x6000r firmware
Product

totolink x6000r firmware

57 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-4611
all versions
A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function set
7.2HIGH
CVE-2025-70328
all versions
TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/
8.8HIGH
CVE-2025-11005
<= 9.4.0cu.1360_b20241207
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows
9.8CRITICAL
CVE-2025-52907
<= 9.4.0cu.1360_b20241207
Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R:
8.8HIGH
CVE-2025-52906
<= 9.4.0cu.1360_b20241207
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows
9.8CRITICAL
CVE-2025-52905
<= 9.4.0cu.1360_b20241207
Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241
7.5HIGH
CVE-2025-52053
all versions
TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the
9.8CRITICAL
CVE-2025-52284
all versions
Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the
6.5MEDIUM
CVE-2025-25524
all versions
Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is r
5.1MEDIUM
CVE-2024-52723
all versions
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering
9.8CRITICAL
CVE-2024-7907
all versions
A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the
6.3MEDIUM
CVE-2024-2353
all versions
A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the
8.8HIGH
CVE-2024-1781
all versions
A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the fu
6.3MEDIUM
CVE-2024-1661
all versions
A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerability is an
2.5LOW
CVE-2023-52040
all versions
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C functi
9.8CRITICAL
CVE-2023-52039
all versions
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 functi
9.8CRITICAL
CVE-2023-52038
all versions
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 functi
9.8CRITICAL
CVE-2023-52042
all versions
An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands vi
9.8CRITICAL
CVE-2023-52041
all versions
An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function o
9.8CRITICAL
CVE-2023-50651
all versions
TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component
9.8CRITICAL
CVE-2023-48800
all versions
In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connect
9.8CRITICAL
CVE-2023-48799
all versions
TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution.
9.8CRITICAL
CVE-2023-48801
all versions
In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connect
9.8CRITICAL
CVE-2023-43455
all versions
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code v
9.8CRITICAL
CVE-2023-43454
all versions
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code v
9.8CRITICAL
CVE-2023-43453
all versions
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code v
9.8CRITICAL
CVE-2023-48812
all versions
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_
9.8CRITICAL
CVE-2023-48811
all versions
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set
9.8CRITICAL
CVE-2023-48810
all versions
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set
9.8CRITICAL
CVE-2023-48808
all versions
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set
9.8CRITICAL
CVE-2023-48807
all versions
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set
9.8CRITICAL
CVE-2023-48806
all versions
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set
9.8CRITICAL
CVE-2023-48805
all versions
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set
9.8CRITICAL
CVE-2023-48804
all versions
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set
9.8CRITICAL
CVE-2023-48803
all versions
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set
9.8CRITICAL
CVE-2023-48802
all versions
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set
9.8CRITICAL
CVE-2023-46485
all versions
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg fun
9.8CRITICAL
CVE-2023-46484
all versions
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.
9.8CRITICAL
CVE-2023-46979
all versions
TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the
9.8CRITICAL
CVE-2023-46978
all versions
TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwor
7.5HIGH
CVE-2023-46424
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4
9.8CRITICAL
CVE-2023-46423
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094
9.8CRITICAL
CVE-2023-46422
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994
9.8CRITICAL
CVE-2023-46421
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00
9.8CRITICAL
CVE-2023-46420
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C
9.8CRITICAL
CVE-2023-46419
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730
9.8CRITICAL
CVE-2023-46418
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688
9.8CRITICAL
CVE-2023-46417
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498
9.8CRITICAL
CVE-2023-46416
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 4
9.8CRITICAL
CVE-2023-46415
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588
9.8CRITICAL
CVE-2023-46414
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D49
9.8CRITICAL
CVE-2023-46413
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function.
9.8CRITICAL
CVE-2023-46412
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function.
9.8CRITICAL
CVE-2023-46411
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.
9.8CRITICAL
CVE-2023-46410
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 functio
9.8CRITICAL
CVE-2023-46409
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.
9.8CRITICAL
CVE-2023-46408
all versions
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 functio
9.8CRITICAL
threatengine.sh