Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-61044


TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function.


Published

2025-10-01T15:15:49.013

Last Modified

2025-10-16T20:15:34.650

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System totolink x18_firmware 9.1.0cu.2053_b20230309 Yes
Hardware totolink x18 - No

References