CVE-2025-61045: Command Injection
Published Oct 1, 2025
·Updated
TOTOLINK X18 V9.1.0cu.2053B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function.
Affected Software
3 affected components
TOTOLINK X18
All of the following
TOTOLINK X18 Firmware=9.1.0cu.2053_b20230309
TOTOLINK X18
Event History
Oct 1, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61045?
CVE-2025-61045 has a high severity rating due to its command injection vulnerability.
2
How do I fix CVE-2025-61045?
To fix CVE-2025-61045, update the TOTOLINK X18 to the latest firmware version provided by the vendor.
3
What systems are affected by CVE-2025-61045?
The CVE-2025-61045 vulnerability affects the TOTOLINK X18 router running version V9.1.0cu.2053_B20230309.
4
What type of vulnerability is CVE-2025-61045?
CVE-2025-61045 is classified as a command injection vulnerability.
5
What is the impact of CVE-2025-61045?
The impact of CVE-2025-61045 can allow an attacker to execute arbitrary commands on the device.