First published: Thu Apr 03 2025(Updated: )
An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TOTOLINK x18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29064 is classified as a critical severity vulnerability due to its potential for remote code execution.
To fix CVE-2025-29064, apply the latest firmware update from TOTOLINK for the x18 model.
CVE-2025-29064 affects the TOTOLINK x18 router version 9.1.0cu.2024_B20220329.
CVE-2025-29064 can be exploited by remote attackers to execute arbitrary code on the affected device.
Currently, the recommended action is to update the device firmware, as there are no official workarounds to mitigate CVE-2025-29064.