A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2025-52906 with a CVSS score of 9.3, has been discovered in TOTOLINK X6000R routers. This flaw allows attackers to execute arbitrary commands on affected devices without authentication, posing a severe risk to users of these widely deployed consumer networking products. The vulnerability is present in firmware version V9.4.0cu.1360_B20241207, which was released on March 28, 2025. In addition to CVE-2025-52906, two other significant vulnerabilities were identified in the same firmware: CVE-2025-52905, an argument injection flaw that can trigger denial-of-service (DoS) conditions, and CVE-2025-52907, a security bypass that could lead to persistent DoS or arbitrary file writes, with the potential for chained attacks resulting in RCE. The unauthenticated command injection vulnerability (CVE-2025-52906) is considered the most critical, as it enables attackers to compromise the device remotely and potentially use it as a foothold for further attacks on connected networks. Palo Alto Networks' Unit 42 team conducted a technical analysis of these vulnerabilities, detailing their root causes and demonstrating their impacts. The widespread use of TOTOLINK routers in consumer and small business environments amplifies the potential impact of these flaws. TOTOLINK has responded by releasing updated firmware to address the vulnerabilities, and users are strongly advised to apply these updates immediately to mitigate risk. Security solutions such as Palo Alto Networks' Next-Generation Firewall and Device Security offerings can help detect and block exploitation attempts. The vulnerabilities highlight the ongoing risks associated with IoT and consumer networking devices, which are often targeted due to their broad deployment and sometimes limited security controls. Attackers exploiting CVE-2025-52906 could gain full control over the router, intercept network traffic, or launch further attacks against internal or external targets. The technical details provided by researchers enable defenders to better understand the attack vectors and implement appropriate mitigations. Organizations and individuals using TOTOLINK X6000R routers should assess their exposure and ensure that all devices are updated to the latest firmware version. The incident underscores the importance of timely vulnerability disclosure and coordinated response between vendors and security researchers. Monitoring for signs of compromise and unusual network activity is recommended for all potentially affected environments. The discovery of these vulnerabilities serves as a reminder of the critical need for robust security practices in the management of network infrastructure devices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A vulnerability report identified CVE-2025-52906 as a critical TOTOLINK X6000R flaw with a CVSS score of 9.3 that allows unauthenticated remote code execution.
Palo Alto Networks Unit 42 disclosed three newly identified vulnerabilities affecting TOTOLINK X6000R routers, including issues that could expose devices to serious compromise.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.