Get real-time updates on Telegram
P3Verified
CVE-2026-105484: A security vulnerability security flaw
CVE-2026-105484. CVSS base score 10.0 (HIGH, Vendor/CNA).
Affected technology
X6000R · 9.4.0cu.652_B20230116
TOTOLINK
Component: UploadFirmwareFile Handler
Function: firmware_check
File: /cgi-bin/cstecgi.cgi
Attack conditions (VulDB, CVSS 4.0): Network (remote) · No privileges required · No user interaction required
What an attacker can do
VulDB’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-77, CWE-78
- CCR priority
- 40.0 /100 (P3)
- CVSS
- 10.0 /10 · AV:N/AC:L/Au:N/C:C/I:C/A:C · Vendor/CNA
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-06 03:43:23.555804+00:00 UTC
- GitHub Advisory Database · Source record · observed 2026-10-06 03:43:59.502831+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-105484.html