CVE-2024-41319: Totolink a6000r Firmware

Critical severity, CVSS 9.8. EPSS: 5.5% chance of exploitation in the next 30 days.

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

Affected products

  • Totolink a6000r Firmware: version 1.0.1-b20201211.2000 only

Published 2024-07-23. Last modified 2026-06-17.