CVE-2026-105484: TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command injection
A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652B20230116. The impacted element is the function firmwarecheck of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument filename leads to os command injection. The attack may be performed from remote.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable and requires no privileges or user interaction. An attacker can manipulate the file_name argument handled by the firmware_check function.
Which device software version is identified as affected?
The reported affected version is TOTOLINK X6000R 9.4.0cu.652_B20230116. No other versions are identified in the available data.
What is the potential impact of successful exploitation?
Successful exploitation can result in operating-system command injection. The provided severity vector indicates potential high impact to confidentiality, integrity, and availability, including effects beyond the vulnerable component.