CVE-2025-29064: Code Injection
Published Apr 3, 2025
·Updated
An issue in TOTOLINK x18 v.9.1.0cu.2024B20220329 allows a remote attacker to execute arbitrary code via the sub410E54 function of the cstecgi.cgi.
Affected Software
3 affected components
TOTOLINK X18
All of the following
TOTOLINK X18 Firmware=9.1.0cu.2024_b20220329
TOTOLINK X18
Event History
Apr 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-29064?
CVE-2025-29064 is classified as a critical severity vulnerability due to its potential for remote code execution.
2
How can I fix CVE-2025-29064?
To fix CVE-2025-29064, apply the latest firmware update from TOTOLINK for the x18 model.
3
What systems are affected by CVE-2025-29064?
CVE-2025-29064 affects the TOTOLINK x18 router version 9.1.0cu.2024_B20220329.
4
What kind of attack can exploit CVE-2025-29064?
CVE-2025-29064 can be exploited by remote attackers to execute arbitrary code on the affected device.
5
Is there a workaround for CVE-2025-29064?
Currently, the recommended action is to update the device firmware, as there are no official workarounds to mitigate CVE-2025-29064.