Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Lzy0522

#25797de 53,634
9.8CVSS total
Vulnerabilidades · 1
PT-2025-17305
9.8
2025-04-18
Totolink · Totolink X18 · CVE-2025-29209
**Name of the Vulnerable Software and Affected Versions** TOTOLINK X18 version 9.1.0cu.2024 B20220329 **Description** The issue concerns an unauthorized arbitrary command execution in the `enable` parameter of the `sub 41105C` function of `cstecgi.cgi`. **Recommendations** For TOTOLINK X18 version 9.1.0cu.2024 B20220329, consider disabling the `sub 41105C` function of `cstecgi.cgi` to prevent exploitation until a patch is available. Restrict access to the `enable` parameter in the affected `cstecgi.cgi` to minimize the risk of unauthorized command execution.