CVE-2026-105484

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Referenced assets1 URL
Full discourse1 post
  • ThreatAft@ThreatAft

    🚨 TOTOLINK X6000R — CVE-2026-105484, CVSS 10.0 Unauth OS command injection in UploadFirmwareFile handler via file_name parameter. 🔗 https://threataft.com/articles/totolink-x6000r-cve-2026-105484?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel #RouterSecurity #CVE #PatchNow

    0000048
    46 followersView on X

Explore more