PT-2025-17305 · Totolink · Totolink X18

Lzy0522

·

Published

2025-04-18

·

Updated

2025-04-29

·

CVE-2025-29209

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK X18 version 9.1.0cu.2024 B20220329
Description The issue concerns an unauthorized arbitrary command execution in the enable parameter of the sub 41105C function of cstecgi.cgi.
Recommendations For TOTOLINK X18 version 9.1.0cu.2024 B20220329, consider disabling the sub 41105C function of cstecgi.cgi to prevent exploitation until a patch is available. Restrict access to the enable parameter in the affected cstecgi.cgi to minimize the risk of unauthorized command execution.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-29209

Affected Products

Totolink X18