CVE-2025-61044: Command Injection
Published Oct 1, 2025
·Updated
TOTOLINK X18 V9.1.0cu.2053B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function.
Affected Software
3 affected components
TOTOLINK X18
All of the following
TOTOLINK X18 Firmware=9.1.0cu.2053_b20230309
TOTOLINK X18
Event History
Oct 1, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61044?
CVE-2025-61044 has been identified as a critical vulnerability due to its potential for remote command injection.
2
How do I fix CVE-2025-61044?
To address CVE-2025-61044, update your TOTOLINK X18 device firmware to the latest version that contains the security patch.
3
What does CVE-2025-61044 affect?
CVE-2025-61044 affects the TOTOLINK X18 devices running firmware version V9.1.0cu.2053_B20230309.
4
What is the exploitation risk of CVE-2025-61044?
Exploitation of CVE-2025-61044 can allow an attacker to execute arbitrary commands on the affected device.
5
Who discovered CVE-2025-61044?
CVE-2025-61044 was discovered by a security researcher during vulnerability assessments on IoT devices.