OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105484

CRITICAL · CVSS 10

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the UploadFirmwareFile Handler of TOTOLINK X6000R firmware version 9.4.0cu.652_B20230116, allowing remote attackers to exploit the firmware_check function through OS command injection via manipulated file_name arguments. This could lead to unauthorized command execution on the affected device, posing significant risks to network integrity and data security. Organizations using this firmware should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-105484
Severity
CRITICAL
CVSS
10
EPSS
N/A

Original NVD Description

A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.