OS Command Injection Vulnerability in TOTOLINK X6000R Router
CVE-2026-105484

10CRITICAL

Key Information:

Vendor

Totolink

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105484?

A security vulnerability has been identified in the TOTOLINK X6000R router firmware version 9.4.0cu.652_B20230116. The flaw exists within the UploadFirmwareFile Handler of the firmware_check function located in /cgi-bin/cstecgi.cgi. By manipulating the file_name argument, an attacker can perform remote OS command injection, potentially compromising the underlying operating system. This vulnerability underscores the importance of securing router firmware against unauthorized access and command execution.

Affected Version(s)

X6000R 9.4.0cu.652_B20230116

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

liumingjie (VulDB User)
VulDB Vulnerability Moderation Team
.