CVE-2023-46423: Totolink x6000r Firmware

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094 function.

Affected products

  • Totolink x6000r Firmware: version 9.4.0cu.652_b20230116 only

Published 2023-10-25. Last modified 2026-06-17.