Back to Database
Status published
Critical
CVE-2025-11005
TOTOLINK X6000R Unauthenticated Command Injection Vulnerability
Vulnerability Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11005
Credits & Attribution
No credits recorded in the NVD database.
References
More from TOTOLINK
View All →CVE-2025-9935
TOTOLINK N600R cstecgi.cgi sub_4159F8 command injection
Medium
6.9
CVE-2025-9934
TOTOLINK X5000R cstecgi.cgi sub_410C34 command injection
Medium
5.3
CVE-2025-9783
TOTOLINK A702R formParentControl sub_418030 buffer overflow
High
8.7
CVE-2025-9782
TOTOLINK A702R formOneKeyAccessButton sub_4466F8 buffer overflow
High
8.7
CVE-2025-9781
TOTOLINK A702R formFilter sub_4162DC buffer overflow
High
8.7
Affected Vendor
TOTOLINK
View all reports →Affected Software
X6000R
Vulnerable Versions:
0
Timeline
Official Publish:
September 25th, 2025
Last Modified:
September 26th, 2025
Added to House:
July 22nd, 2026