Impact
A remote attacker can manipulate the 'file_name' parameter of the firmware_check function in /cgi-bin/cstecgi.cgi, causing an OS command injection that permits execution of arbitrary shell commands on the device, potentially leading to full control over the router and compromising confidentiality, integrity, and availability.
Affected Systems
TOTOLINK X6000R routers running firmware version 9.4.0cu.652_B20230116 are affected, and any similar model using the same upload firmware handler may also be vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 10 with no EPSS data, and is not listed in the CISA KEV catalog; exploitation requires remote access to the device through the admin interface and can be achieved by sending a crafted request to the UploadFirmwareFile handler, making it highly likely to be abused if the appliance is exposed to the Internet.
OpenCVE Enrichment