{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3htotolinkx6000r9.4.0cu.652_b20230116/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:totolink:x6000r:9.4.0cu.652_b20230116:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-105484"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["X6000R (9.4.0cu.652_B20230116)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","cve","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["TOTOLINK"],"content_html":"\u003cp\u003eCVE-2026-105484 identifies a critical security vulnerability in the TOTOLINK X6000R router, specifically affecting firmware version 9.4.0cu.652_B20230116. The vulnerability exists within the 'UploadFirmwareFile' handler, which processes requests through the '/cgi-bin/cstecgi.cgi' script. An attacker can manipulate the 'file_name' argument during a firmware upload operation to inject arbitrary OS commands.\u003c/p\u003e\n\u003cp\u003eBecause this vulnerability is accessible remotely and does not appear to require authentication, it represents a significant risk for device takeover. Successful exploitation allows for complete administrative control over the affected network equipment, enabling further malicious activities such as traffic interception, persistent backdoor installation, and pivoting into the local network. Defenders should monitor web server logs for irregular requests targeting the specified CGI endpoint, specifically looking for shell metacharacters in query parameters.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote code execution on the affected router. This level of access grants the attacker the ability to reconfigure the device, exfiltrate network data, or use the device as an initial access point for lateral movement within the target network. Given that this affects router firmware, it could lead to sustained device compromise if not addressed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server traffic for POST requests to /cgi-bin/cstecgi.cgi that contain suspicious shell metacharacters in the file_name parameter.\u003c/li\u003e\n\u003cli\u003eRestrict access to the management interface of TOTOLINK X6000R devices to trusted administrative IP addresses only.\u003c/li\u003e\n\u003cli\u003eReview device logs for unauthorized firmware modification attempts or unexpected process execution initiated by the web server process.\u003c/li\u003e\n\u003cli\u003eConsult the vendor for firmware updates that address the insecure handling of the file_name argument in the UploadFirmwareFile handler.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T02:51:48Z","date_published":"2026-10-06T02:51:48Z","id":"https://feed.craftedsignal.io/briefs/2026-10-totolink-cve-2026-105484/","summary":"A critical command injection vulnerability in the TOTOLINK X6000R firmware allows unauthenticated remote attackers to execute arbitrary system commands via the /cgi-bin/cstecgi.cgi endpoint.","title":"Remote Command Injection in TOTOLINK X6000R Firmware","url":"https://feed.craftedsignal.io/briefs/2026-10-totolink-cve-2026-105484/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:h:totolink:x6000r:9.4.0cu.652_b20230116:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}