PT-2025-17305 · Totolink · Totolink X18

·

CVE-2025-29209

·

Published

2025-04-18

·

Updated

2025-04-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK X18 version 9.1.0cu.2024 B20220329
Description The issue concerns an unauthorized arbitrary command execution in the enable parameter of the sub 41105C function of cstecgi.cgi.
Recommendations For TOTOLINK X18 version 9.1.0cu.2024 B20220329, consider disabling the sub 41105C function of cstecgi.cgi to prevent exploitation until a patch is available. Restrict access to the enable parameter in the affected cstecgi.cgi to minimize the risk of unauthorized command execution.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29209

Affected Products

Totolink X18