CVE-2025-52284: Totolink x6000r Firmware

Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.

Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.

Affected products

  • Totolink x6000r Firmware: version 9.4.0cu.1360_b20241207 only

Published 2025-07-29. Last modified 2026-06-17.