CVE-2025-52907
BaseFortify
Publication date: 2025-09-24
Last updated on: 2025-10-14
Assigner: Palo Alto Networks, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| totolink | x6000r_firmware | to 9.4.0cu.1360_b20241207 (inc) |
| totolink | x6000r | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Input Validation issue in the TOTOLINK X6000R router, which allows attackers to perform Command Injection and File Manipulation. This means that the device does not properly check or sanitize input data, enabling malicious actors to execute unauthorized commands or manipulate files on the device.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized command execution and file manipulation on the affected device, potentially allowing attackers to take control of the device, disrupt its normal operation, access sensitive information, or use the device as a foothold for further attacks within a network.