Skip to content
COOEY

FAIL › dossier

x6000r

PRODUCT

· dossier confidence 80%

TOTOLINK X6000R is a wireless router that suffered two critical RCE vulnerabilities in 2023 and 2024, indicating a pattern of unpatched edge-device flaws.

PROFILE
Categorynetworking hardwareWhat they doTOTOLINK X6000R is a wireless router manufactured by TOTOLINK.
SECURITY POSTURE

TOTOLINK X6000R has a poor security posture, evidenced by two critical remote code execution (RCE) vulnerabilities in 2023 and 2024 affecting the device's firmware.

Notable failures
  • CVE-2024-52723 critical RCE via shttpd Uci_Set Str function
  • CVE-2023-50651 critical RCE via /cgi-bin/cstecgi.cgi
Patterns: repeated unpatched edge-device RCEs
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2024-11-22 CVE-2024-52723 critical In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
2023-12-30 CVE-2023-50651 critical TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
Open questions: TOTOLINK corporate headquarters location · TOTOLINK founding year
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-22 04:14:20.468159+00:00