CVE-2023-50651
published 2023-12-30CVE-2023-50651: TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.52%
71.6th percentile
TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | x6000r_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Totolink X6000R 9.4.0cu.852_B20230719 /cgi-bin/cstecgi.cgi os command injection
vuldb·2026-07-10·CVSS 9.8
CVE-2023-50651 [CRITICAL] Totolink X6000R 9.4.0cu.852_B20230719 /cgi-bin/cstecgi.cgi os command injection
A vulnerability was found in Totolink X6000R 9.4.0cu.852_B20230719 and classified as critical. This affects an unknown function of the file /cgi-bin/cstecgi.cgi. Executing a manipulation can lead to os command injection.
This vulnerability is registered as CVE-2023-50651. It is possible to launch the attack remotely. No exploit is available.
GHSA
GHSA-mv97-cv2v-gqc7: TOTOLINK X6000R v9
ghsa_unreviewed·2023-12-30
CVE-2023-50651 [CRITICAL] CWE-78 GHSA-mv97-cv2v-gqc7: TOTOLINK X6000R v9
TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-12-30
Published