CVE-2026-105484 is a critical (CVSS 10.0) OS command injection flaw in the firmware upload handler of the TOTOLINK X6000R router, and attackers can exploit it remotely without authentication.
What Is It
CVE-2026-105484 is an OS command injection vulnerability in TOTOLINK X6000R firmware version 9.4.0cu.652_B20230116. It sits in the firmware_check function of /cgi-bin/cstecgi.cgi, inside the UploadFirmwareFile Handler component. An attacker who manipulates the file_name argument can inject operating system commands, and the attack can be carried out remotely.
The weakness is classified as CWE-77 (Command Injection) and CWE-78 (OS Command Injection). VulDB, acting as CNA, submitted the record. NVD published it on October 6, 2026, and its status is still "Received."
Why It Matters
VulDB rates this flaw at the top of every CVSS scale:
- CVSS 3.1: 10.0 CRITICAL (
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) - CVSS 4.0: 10.0 CRITICAL
- CVSS 2.0: 10.0
The vector shows the attack works over the network, needs little effort, and requires no privileges or user interaction. The scope is marked as changed, and confidentiality, integrity and availability impacts are all rated high. In practice, an unauthenticated attacker who can reach the vulnerable endpoint could run arbitrary commands on the device.
The supplied data does not confirm any active exploitation. The CVSS 4.0 exploit maturity field is "Not Defined."
What's Vulnerable
- Vendor: TOTOLINK
- Product: X6000R
- Affected version: 9.4.0cu.652_B20230116
- Component: UploadFirmwareFile Handler (
/cgi-bin/cstecgi.cgi,firmware_checkfunction) - CPE:
cpe:2.3:o:totolink:x6000r_firmware:*:*:*:*:*:*:*:*
The record names only this firmware build as affected. It does not say whether other versions are vulnerable.
Patch Status
The NVD record does not mention a vendor patch, fixed firmware version or official advisory. Owners of the X6000R should watch TOTOLINK's site for updated firmware. Until a fix is available, they should limit who can reach the device's web management interface.