CVE-2023-50651: Totolink x6000r Firmware

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.

Affected products

  • Totolink x6000r Firmware: version 9.4.0cu.852_b20230719 only

Published 2023-12-30. Last modified 2026-07-09.