CRITICAL 10.0 NVD
CVE-2026-105484
A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cs
A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.
References
- https://vuldb.com/cve/CVE-2026-105484
- https://vuldb.com/submit/984434
- https://vuldb.com/vuln/413619
- https://vuldb.com/vuln/413619/cti
- https://www.totolink.net/
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-10-06 via NVD.
Risk Timeline
CVE Disclosed2026-10-06 · -1 days ago
Remediation Resources
Official Advisory
vuldb.com/cve/CVE-2026-105484Official Advisory
vuldb.com/vuln/413619Analysis & PoC
vuldb.com/submit/984434Analysis & PoC
www.totolink.net/
vulnfeed aggregates 11356 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.