CVE-2025-70328 | Totolink X6000R up to 9.4.0cu.1498_B20250826 /usr/sbin/shttpd NTPSyncWithHost host_time os command injection
A vulnerability categorized as critical has been discovered in Totolink X6000R up to 9.4.0cu.1498_B20250826. This impacts the function NTPSyncWithHost of the file /usr/sbin/shttpd. Executing a manipulation of the argument host_time can lead to os command injection.
This vulnerability appears as CVE-2025-70328. The attack may be performed from remote. There is no available exploit.