CVE-2026-1723: Totolink x6000r
Critical severity, CVSS 9.2. EPSS: 1% chance of exploitation in the next 30 days.
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1498_B20250826.
Affected products
- Totolink x6000r: up to and including V9.4.0cu.1498_B20250826
Published 2026-01-30. Last modified 2026-06-17.