Cyber & AI intelligence
Wasteland.
Briefs indexed3027
Issues31
Published Mondays07:30 CT
CVE · Critical CVE-2026-105484 2026-10-06

TOTOLINK X6000R Router Flaw Allows Remote OS Command Injection (CVE-2026-105484)

"CVE-2026-105484 is a critical (CVSS 10.0) OS command injection flaw in the firmware upload handler of the TOTOLINK X6000R router, and attackers can exploit it remotely without authentication."

CVE-2026-105484 is a critical (CVSS 10.0) OS command injection flaw in the firmware upload handler of the TOTOLINK X6000R router, and attackers can exploit it remotely without authentication.

What Is It

CVE-2026-105484 is an OS command injection vulnerability in TOTOLINK X6000R firmware version 9.4.0cu.652_B20230116. It sits in the firmware_check function of /cgi-bin/cstecgi.cgi, inside the UploadFirmwareFile Handler component. An attacker who manipulates the file_name argument can inject operating system commands, and the attack can be carried out remotely.

The weakness is classified as CWE-77 (Command Injection) and CWE-78 (OS Command Injection). VulDB, acting as CNA, submitted the record. NVD published it on October 6, 2026, and its status is still "Received."

Why It Matters

VulDB rates this flaw at the top of every CVSS scale:

The vector shows the attack works over the network, needs little effort, and requires no privileges or user interaction. The scope is marked as changed, and confidentiality, integrity and availability impacts are all rated high. In practice, an unauthenticated attacker who can reach the vulnerable endpoint could run arbitrary commands on the device.

The supplied data does not confirm any active exploitation. The CVSS 4.0 exploit maturity field is "Not Defined."

What's Vulnerable

The record names only this firmware build as affected. It does not say whether other versions are vulnerable.

Patch Status

The NVD record does not mention a vendor patch, fixed firmware version or official advisory. Owners of the X6000R should watch TOTOLINK's site for updated firmware. Until a fix is available, they should limit who can reach the device's web management interface.

Sources