Impact
The vulnerability is an OS Command Injection flaw that allows attackers to execute arbitrary system commands without authentication. Because victim systems accept unsanitized input, an attacker can compromise confidentiality, integrity, and availability of the device. The flaw is classified as CWE‑78."
Affected Systems
TOTOLINK X6000R routers running firmware versions up to V9.4.0cu.1498_B20250826 are affected; newer firmware revisions beyond that release are not known to be vulnerable.
Risk and Exploitability
With a CVSS score of 9.2 the vulnerability is considered critical. The EPSS score of less than 1% indicates a low probability of exploitation in the current landscape, but the flaw is not listed in CISA’s KEV catalog. Exploitation requires no credentials and can be carried out over the network from any remote host that can reach the exposed management interface, giving attackers full control over the device and potentially the underlying network.
OpenCVE Enrichment