CVE-2025-52906

Published Sep 24, 2025

Last updated 5 months ago

Overview

Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
Source
psirt@paloaltonetworks.com
NVD status
Analyzed
Products
x6000r_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@paloaltonetworks.com
CWE-78

Social media

Hype score
Not currently trending
  1. #VulnerabilityReport #CommandInjection Critical Flaw CVE-2025-52906 (CVSS 9.3) Allows Unauthenticated RCE on TOTOLINK X6000R Routers https://t.co/AV8yHvSc5p

    @Komodosec

    8 Nov 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Critical vulnerabilities (CVE-2025-52905, CVE-2025-52906, CVE-2025-52907) in TOTOLINK X6000R routers allow unauthenticated attackers to execute commands via the web interface. Update to patched firmware V9.4.0cu.1498_B20250826 to prevent attacks

    @bigmacd16684

    7 Oct 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ⚠️ TOTOLINK X6000R vulnerabilities disclosed: 3 critical CVEs including CVE-2025-52906 (CVSS 9.3) enable unauthenticated RCE. Botnet exploitation highly likely. CORTEX: Patch to firmware V9.4.0cu.1498 immediately. Mass scanning expected. https://t.co/r1ZXOG8qsl

    @the_c_protocol

    3 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 𝐂𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐅𝐥𝐚𝐰 𝐂𝐕𝐄-𝟐𝟎𝟐𝟓-𝟓𝟐𝟗𝟎𝟔 𝐀𝐥𝐥𝐨𝐰𝐬 𝐔𝐧𝐚𝐮𝐭𝐡𝐞𝐧𝐭𝐢𝐜𝐚𝐭𝐞𝐝 𝐑𝐂𝐄 𝐨𝐧 𝐓𝐎𝐓𝐎𝐋𝐈𝐍𝐊 𝐗𝟔𝟎𝟎𝟎𝐑 𝐑𝐨

    @PurpleOps_io

    2 Oct 2025

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 New Alert: CVE-2025-52906 🌐🔒 High-risk OS Command Injection in TOTOLINK X6000R firmware versions up to V9.4.0cu.1360_B20241207! Vulnerable devices are at risk of exploitation in the next 30 days. Update now to keep your network secure! 🔧💻 #CyberSecurity #Infosec

    @SecAideInfo

    27 Sept 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-52906 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue aff… https://t.co/Uw08YsDIhB

    @CVEnew

    24 Sept 2025

    241 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2025-52906: CRITICAL] TOTOLINK X6000R is vulnerable to OS Command Injection flaw up to version V9.4.0cu.1360_B20241207. An attacker can execute malicious commands on the system.#cve,CVE-2025-52906,#cybersecurity https://t.co/6jnnzeNIlQ https://t.co/a5Cd9mFbBo

    @CveFindCom

    24 Sept 2025

    73 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations