Skip to content
COOEY

FAIL › dossier

x6000r firmware

PRODUCT

· dossier confidence 0%

TOTOLINK's X6000R firmware has suffered multiple critical RCE vulnerabilities, revealing systemic weaknesses in input validation and patch management for their networking hardware.

PROFILE
Categorynetwork hardwareWhat they doTOTOLINK manufactures and sells wireless router and networking hardware.
SECURITY POSTURE

TOTOLINK has a poor security track record with multiple critical remote code execution (RCE) vulnerabilities in its X6000R firmware, indicating a lack of rigorous input validation and patch management.

Notable failures
  • CVE-2024-52723: RCE via unfiltered Uci_Set Str in shttpd
  • CVE-2023-50651: RCE via /cgi-bin/cstecgi.cgi
Patterns: repeated unpatched edge-device RCEs; lack of strict parameter filtering in web components
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2024-11-22 CVE-2024-52723 critical In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
2023-12-30 CVE-2023-50651 critical TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
Open questions: TOTOLINK's founding year and headquarters location · TOTOLINK's company size and ownership structure
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-22 04:13:22.524163+00:00