CPE
A critical command injection vulnerability in the TOTOLINK X6000R firmware allows unauthenticated remote attackers to execute arbitrary system commands via the /cgi-bin/cstecgi.cgi endpoint.