TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function.
2025-10-01T15:15:49.013
2025-10-16T20:15:34.650
Modified
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | totolink | x18_firmware | 9.1.0cu.2053_b20230309 | Yes |
| Hardware | totolink | x18 | - | No |