Description
A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection. The attack may be launched remotely.
Problem types
Product status
9.4.0cu.1498_B20250826
Timeline
| 2026-03-23: | Advisory disclosed |
| 2026-03-23: | VulDB entry created |
| 2026-03-23: | VulDB entry last update |
Credits
1935648903 (VulDB User)
VulDB
References
vuldb.com/?id.352475 (VDB-352475 | TOTOLINK X6000R shttpd setLanCfg privilege escalation)
vuldb.com/?ctiid.352475 (VDB-352475 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.775642 (Submit #775642 | Totolink X6000R V9.4.0cu.1360_B20241207/V9.4.0cu.1498_B20250826 OS Command Injection)
www.totolink.net/