📦 X6000r Firmware

by Totolink

🔍 What is X6000r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-11005

CRITICAL CVSS 9.8 Sep 25, 2025

This CVE describes an OS command injection vulnerability in TOTOLINK X6000R routers that allows attackers to execute arbitrary commands on the device. Attackers can potentially gain full control of af...

CVE-2025-52053

CRITICAL CVSS 9.8 Sep 15, 2025

This is a critical command injection vulnerability in TOTOLINK X6000R routers that allows unauthenticated attackers to execute arbitrary commands on affected devices. Attackers can exploit this vulner...

CVE-2024-52723

CRITICAL CVSS 9.8 Nov 22, 2024

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers by exploiting insufficient parameter filtering in the shttpd file's Uci_Set Str function. Attackers ...

CVE-2023-52038

CRITICAL CVSS 9.8 Jan 24, 2024

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers through the sub_415C80 function. Attackers can gain full control of affected devices without authent...

CVE-2023-52040

CRITICAL CVSS 9.8 Jan 24, 2024

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via the sub_41284C function. Attackers can gain full control of affected devices without authenticat...

CVE-2023-52041

CRITICAL CVSS 9.8 Jan 16, 2024

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK X6000R routers by exploiting a flaw in the shttpd program's sub_410118 function. Attackers can gain full control of aff...

CVE-2023-48799

CRITICAL CVSS 9.8 Dec 4, 2023

CVE-2023-48799 is a command execution vulnerability in TOTOLINK-X6000R routers running vulnerable firmware versions. Attackers can execute arbitrary commands on affected devices, potentially gaining f...

CVE-2023-48801

CRITICAL CVSS 9.8 Dec 1, 2023

This vulnerability allows remote command execution on TOTOLINK X6000R routers by exploiting improper input validation in the shttpd component. Attackers can inject arbitrary commands through front-end...

CVE-2023-43453

CRITICAL CVSS 9.8 Dec 1, 2023

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK X6000R routers by exploiting improper input validation in the setDiagnosisCfg component's IP parameter. Attackers can g...

CVE-2023-43455

CRITICAL CVSS 9.8 Dec 1, 2023

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK X6000R routers via the command parameter in the setting/setTracerouteCfg component. Attackers can gain full control of ...

CVE-2023-48808

CRITICAL CVSS 9.8 Nov 30, 2023

This CVE describes a command injection vulnerability in TOTOLINK X6000R routers where improper input validation in the shttpd component allows attackers to execute arbitrary commands. Attackers can ex...

CVE-2023-48811

CRITICAL CVSS 9.8 Nov 30, 2023

This CVE describes a command injection vulnerability in TOTOLINK X6000R routers where improper input validation in the shttpd component allows attackers to execute arbitrary commands. Attackers can ex...

CVE-2023-48802

CRITICAL CVSS 9.8 Nov 30, 2023

This CVE describes a command injection vulnerability in TOTOLINK X6000R routers where improper input validation in the shttpd component allows attackers to execute arbitrary commands. Attackers can ex...

CVE-2023-48804

CRITICAL CVSS 9.8 Nov 30, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers by exploiting improper input validation in the shttpd component. Attackers can achieve full system c...

CVE-2023-48806

CRITICAL CVSS 9.8 Nov 30, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers by exploiting improper input validation in the shttpd service. Attackers can gain full control of af...

CVE-2023-46484

CRITICAL CVSS 9.8 Oct 31, 2023

This vulnerability allows remote attackers to execute arbitrary code on TOTOlink X6000R routers via the setLedCfg function. Attackers can gain full control of affected devices without authentication. ...

CVE-2023-46979

CRITICAL CVSS 9.8 Oct 31, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via command injection in the setLedCfg function. Attackers can gain full control of affected devices...

CVE-2023-46409

CRITICAL CVSS 9.8 Oct 25, 2023

This CVE describes a command execution vulnerability in TOTOLINK X6000R routers that allows attackers to execute arbitrary commands on the device. The vulnerability exists in the sub_41CC04 function a...

CVE-2023-46411

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via the sub_415258 function. It affects users running vulnerable firmware versions, potentially enab...

CVE-2023-46413

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via the sub_4155DC function. Attackers can gain full control of affected devices, potentially compro...

CVE-2025-70328

HIGH CVSS 8.8 Feb 23, 2026

This CVE describes an OS command injection vulnerability in TOTOLINK X6000R routers. Authenticated attackers can execute arbitrary shell commands by exploiting insufficient input validation in the NTP...

CVE-2023-46978

HIGH CVSS 7.5 Oct 31, 2023

This vulnerability allows unauthenticated attackers to reset the admin login password and WiFi passwords on TOTOLINK X6000R routers. Attackers can gain unauthorized access to router administration and...

CVE-2025-52284

MEDIUM CVSS 6.5 Jul 29, 2025

This CVE describes an unauthenticated command injection vulnerability in Totolink X6000R routers. Attackers can execute arbitrary system commands by sending specially crafted requests to the vulnerabl...

CVE-2024-7907

MEDIUM CVSS 6.3 Aug 18, 2024

This critical vulnerability in TOTOLINK X6000R routers allows remote attackers to execute arbitrary commands via command injection in the setSyslogCfg function. Attackers can exploit this to gain full...