Totolink
Totolink X18 Firmware: vulnerabilidades y CVE
Totolink X18 Firmware tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-61045 | Crítica (9.8) | 1.5% | — | 1 oct 2025 | TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function. |
| CVE-2025-61044 | Crítica (9.8) | 1.0% | — | 1 oct 2025 | TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function. |
| CVE-2025-29209 | Crítica (9.8) | 1.2% | — | 18 abr 2025 | TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .cgi. |
| CVE-2025-29064 | Crítica (9.8) | 0.79% | — | 3 abr 2025 | An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi. |
| CVE-2025-1829 | Media (5.3) | 12% | — | 2 mar 2025 | A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been declared as critical. This vulnerability affects the function setMtknatCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument… |
| CVE-2025-1340 | Alta (8.7) | 17% | — | 16 feb 2025 | A vulnerability classified as critical has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation as part of String leads to… |
| CVE-2025-1339 | Media (5.3) | 2.6% | — | 16 feb 2025 | A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been rated as critical. This issue affects the function setL2tpdConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable… |
| CVE-2024-10966 | Media (5.3) | 3.2% | — | 7 nov 2024 | A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the… |
| CVE-2023-29803 | Crítica (9.8) | 2.1% | — | 14 abr 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function. |
| CVE-2023-29802 | Crítica (9.8) | 2.0% | — | 14 abr 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function. |
| CVE-2023-29801 | Crítica (9.8) | 2.0% | — | 14 abr 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function. |
| CVE-2023-29800 | Crítica (9.8) | 2.0% | — | 14 abr 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function. |
| CVE-2023-29799 | Crítica (9.8) | 2.0% | — | 14 abr 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function. |
| CVE-2023-29798 | Crítica (9.8) | 2.0% | — | 14 abr 2023 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.