---
id: CVE-2026-105484
title: >-
  TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command
  injection
summary: >-
  A security vulnerability has been detected in TOTOLINK X6000R
  9.4.0cu.652_B20230116. The impacted element is the function firmware_check of
  the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler.
  Such manipulation of t…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:R'
cvssSource: cna
cwe:
  - CWE-78
  - CWE-77
vendor: TOTOLINK
product: X6000R
affected:
  - X6000R 9.4.0cu.652_B20230116
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T01:00:19.684Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-105484'
references:
  - url: 'https://vuldb.com/vuln/413619'
    label: >-
      VDB-413619 | TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check
      os command injection
  - url: 'https://vuldb.com/vuln/413619/cti'
    label: 'VDB-413619 | CTI Indicators (IOB, IOC, TTP, IOA)'
  - url: 'https://vuldb.com/cve/CVE-2026-105484'
    label: CVE-2026-105484 | CVE Analysis and Report
  - url: 'https://vuldb.com/submit/984434'
    label: >-
      Submit #984434 | TOTOLINK X6000R 9.4.0cu.652_B20230116 CWE-78 OS Command
      Injection
  - url: 'https://www.totolink.net/'
tags:
  - cve.org
ingestedAt: '2026-10-06T01:38:44.804Z'
---

## Overview

A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.

## Affected

- `X6000R 9.4.0cu.652_B20230116`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
