Improper Input Validation in TOTOLINK X6000R Device
CVE-2025-52907

7.3HIGH

Key Information:

Vendor

Totolink

Status
Vendor
CVE Published:
24 September 2025

What is CVE-2025-52907?

The TOTOLINK X6000R device is impacted by a vulnerability that stems from improper input validation, allowing attackers to execute commands and manipulate files on the device. This type of vulnerability can lead to unauthorized access and control, posing significant risks to the integrity and confidentiality of the device's data. Users of the X6000R should take immediate action to mitigate this issue by applying the latest updates and adhering to security best practices.

Affected Version(s)

X6000R 0

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52907 : Improper Input Validation in TOTOLINK X6000R Device