← Vulnerability feed

Vulnerability record · CVE-2024-1781 · published 23 February 2024

CVE-2024-1781: Totolink x6000r firmware command injection vulnerability

TTotolink · X6000r Firmware

A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The identifier VDB-254573 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

9.8 CVSS 3.1 Critical EPSS 15% · top 3.4% CWE-77 · Command injection
9.8CVSS 3.1 base score, v2 5.8
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The identifier VDB-254573 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1781 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-52053Totolink x6000r firmware command injection vulnerabilityTOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter…EPSS 4.4%9.8CVE-2024-52723Totolink x6000r firmware os command injection vulnerabilityIn TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can a…EPSS 1.0%9.8CVE-2023-52038Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.EPSS 0.77%9.8CVE-2023-52039Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.EPSS 0.77%9.8CVE-2023-52040Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.EPSS 0.85%9.8CVE-2023-52042Totolink x6000r firmware command injection vulnerabilityAn issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parame…EPSS 0.95%9.8CVE-2023-52041Totolink x6000r firmware vulnerabilityAn issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd progra…EPSS 0.86%9.8CVE-2023-50651Totolink x6000r firmware os command injection vulnerabilityTOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cg…EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2024-1781), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.