Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
2025-07-29T18:15:30.433
2025-08-06T16:55:28.277
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | x6000r_firmware | 9.4.0cu.1360_b20241207 | Yes |
Hardware | totolink | x6000r | - | No |