CRITICAL 10.0 NVD

CVE-2026-105484

A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cs

A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.

References

Published: 2026-10-06 · Source: NVD · Feed updated: 2026-10-06
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-10-06 via NVD.

Risk Timeline

CVE Disclosed2026-10-06 · -1 days ago

Remediation Resources

Official Advisory
vuldb.com/vuln/413619
Analysis & PoC
www.totolink.net/
vulnfeed aggregates 11356 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.