TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
2023-04-14T14:15:11.170
2025-02-06T21:15:19.353
Modified
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | totolink | x18_firmware | 9.1.0cu.2024_b20220329 | Yes |
| Hardware | totolink | x18 | - | No |