Summary
CVE-2026-105484 is a critical, unauthenticated OS command injection vulnerability in the firmware upload handler of the TOTOLINK X6000R wireless router. The flaw resides in the firmware_check function of the UploadFirmwareFile handler, reachable via /cgi-bin/cstecgi.cgi, and allows a remote attacker to execute arbitrary operating system commands on the device without any authentication. The issue is rated CRITICAL with a maximum CVSS v3.1 base score of 10.0.
Technical details
- Root cause: The
firmware_checkfunction fails to properly sanitize thefile_nameparameter before using it in a system-level operation, enabling OS command injection (CWE-78 / CWE-77). - Trigger conditions: An attacker submits a crafted
file_namevalue to the firmware upload endpoint (UploadFirmwareFilehandler) on/cgi-bin/cstecgi.cgi. - Attack vector: Network-based and does not require authentication or any user interaction, making it exploitable by any remote attacker who can reach the device’s management interface.
- Impact: Full compromise of confidentiality, integrity, and availability of the device — successful exploitation can lead to arbitrary command execution with the privileges of the web management process, potentially resulting in complete device takeover.
Affected software
- TOTOLINK X6000R, firmware version 9.4.0cu.652_B20230116
Severity
- CVSS v3.1 Base Score: 10.0 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No vendor-supplied patched firmware version has been publicly confirmed as of this writing. Check the TOTOLINK official website for firmware updates for the X6000R and apply any available update immediately.
- If no patch is available:
- Restrict access to the device’s web management interface (
/cgi-bin/cstecgi.cgi) so it is not reachable from the public internet. - Place management interfaces behind a VPN or firewall rule limiting access to trusted internal networks/IPs only.
- Disable remote/WAN-side administration on the router if not strictly required.
- Monitor for unexpected firmware upload requests or anomalous outbound connections from the device.
- Consider replacing or isolating end-of-life TOTOLINK devices that do not receive security updates.
- Restrict access to the device’s web management interface (

