Skip to main content

Vendor/product archive

totolink / x18 CVEs

Beta · best-effort

14 CVEs tagged to totolink / x1810 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-61045

Published Oct 1, 2025

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-61044

Published Oct 1, 2025

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-29209

Published Apr 18, 2025

TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .cgi.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-29064

Published Apr 3, 2025

An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1829

Published Mar 2, 2025

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been declared as critical. This vulnerability affects the function setMtknatCfg of the file /cgi-bin/cstec…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
40.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-1340

Published Feb 16, 2025

A vulnerability classified as critical has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipul…

CVSS 8.7 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-1339

Published Feb 16, 2025

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been rated as critical. This issue affects the function setL2tpdConfig of the file /cgi-bin/cstecgi.cgi. T…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2024-10966

Published Nov 7, 2024

A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29803

Published Apr 14, 2023

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-29802

Published Apr 14, 2023

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-29801

Published Apr 14, 2023

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg funct…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-29800

Published Apr 14, 2023

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-29799

Published Apr 14, 2023

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-29798

Published Apr 14, 2023

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1