Skip to content
Threat Feed
critical advisory

Remote Command Injection in TOTOLINK X6000R Firmware

A critical command injection vulnerability in the TOTOLINK X6000R firmware allows unauthenticated remote attackers to execute arbitrary system commands via the /cgi-bin/cstecgi.cgi endpoint.

CVE search metadata

CVE search record: CVE-2026-105484. Severity: critical. CVSS: 10.0. KEV: no. Product: X6000R (9.4.0cu.652_B20230116). Brief: Remote Command Injection in TOTOLINK X6000R Firmware. Brief link: https://feed.craftedsignal.io/briefs/2026-10-totolink-cve-2026-105484/

CVE-2026-105484 identifies a critical security vulnerability in the TOTOLINK X6000R router, specifically affecting firmware version 9.4.0cu.652_B20230116. The vulnerability exists within the 'UploadFirmwareFile' handler, which processes requests through the '/cgi-bin/cstecgi.cgi' script. An attacker can manipulate the 'file_name' argument during a firmware upload operation to inject arbitrary OS commands.

Because this vulnerability is accessible remotely and does not appear to require authentication, it represents a significant risk for device takeover. Successful exploitation allows for complete administrative control over the affected network equipment, enabling further malicious activities such as traffic interception, persistent backdoor installation, and pivoting into the local network. Defenders should monitor web server logs for irregular requests targeting the specified CGI endpoint, specifically looking for shell metacharacters in query parameters.

Impact

Successful exploitation results in full remote code execution on the affected router. This level of access grants the attacker the ability to reconfigure the device, exfiltrate network data, or use the device as an initial access point for lateral movement within the target network. Given that this affects router firmware, it could lead to sustained device compromise if not addressed.

Recommendation

  • Monitor web server traffic for POST requests to /cgi-bin/cstecgi.cgi that contain suspicious shell metacharacters in the file_name parameter.
  • Restrict access to the management interface of TOTOLINK X6000R devices to trusted administrative IP addresses only.
  • Review device logs for unauthorized firmware modification attempts or unexpected process execution initiated by the web server process.
  • Consult the vendor for firmware updates that address the insecure handling of the file_name argument in the UploadFirmwareFile handler.

Immediate actions

Deploy Sigma rule for CVE-2026-105484 to detect exploitation attempts.

Detection Engineering 24h

Threat Hunt

Search web logs for suspicious characters in cstecgi.cgi requests.

T1203 high high confidence hunt now

Data: webserver access logs

Detection coverage 1

Detects CVE-2026-105484 Exploitation - Command Injection in cstecgi.cgi

critical

Detects exploitation of CVE-2026-105484 by identifying shell metacharacters within the file_name parameter of the cstecgi.cgi script.

sigma tactics: execution, initial_access techniques: T1203 sources: webserver

Detection queries are available on the platform. Get full rules →