CVE-2025-29209: Command Injection
Published Apr 18, 2025
·Updated
TOTOLINK X18 v9.1.0cu.2024B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub41105C function of cstecgi .cgi.
Affected Software
3 affected components
TOTOLINK X18
All of the following
TOTOLINK X18 Firmware=9.1.0cu.2024_b20220329
TOTOLINK X18
Event History
Apr 18, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-29209?
CVE-2025-29209 is classified as a high severity vulnerability due to its potential for unauthorized arbitrary command execution.
2
How do I fix CVE-2025-29209?
To mitigate CVE-2025-29209, users should update their TOTOLINK X18 firmware to the latest version provided by the vendor.
3
What does CVE-2025-29209 exploit?
CVE-2025-29209 exploits the unauthorized arbitrary command execution vulnerability in the enable parameter of the sub_41105C function in cstecgi.cgi.
4
Which version of TOTOLINK X18 is affected by CVE-2025-29209?
CVE-2025-29209 affects TOTOLINK X18 version v9.1.0cu.2024_B20220329.
5
What are the potential risks associated with CVE-2025-29209?
If exploited, CVE-2025-29209 can allow attackers to execute arbitrary commands, leading to full system compromise and data leakage.