CVE-2026-105484Critical· 10.0▾ MidnightA security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of t…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.
X6000R 9.4.0cu.652_B20230116Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14586Medium· 6.3A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224
CVE-2026-100896Critical· 9.9A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030
CVE-2026-91853High· 7.4A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224
CVE-2026-93742Critical· 9.9A weakness has been identified in Totolink A3002MU Hh-B20211125.1046
CVE-2026-105286Medium· 6.3A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455
CVE-2026-105285Critical· 10.0A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455