CVE-2025-52906: Totolink x6000r Firmware
Critical severity, CVSS 9.8. EPSS: 12.8% chance of exploitation in the next 30 days.
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
Affected products
- Totolink x6000r Firmware: up to and including 9.4.0cu.1360_b20241207
Published 2025-09-24. Last modified 2026-06-17.