Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2024-10966

Disclosure Date: November 07, 2024 (last updated December 18, 2024)
A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2023-29803

Disclosure Date: April 14, 2023 (last updated October 08, 2023)
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function.
Attacker Value
Unknown

CVE-2023-29802

Disclosure Date: April 14, 2023 (last updated October 08, 2023)
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.
Attacker Value
Unknown

CVE-2023-29801

Disclosure Date: April 14, 2023 (last updated October 08, 2023)
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function.
Attacker Value
Unknown

CVE-2023-29800

Disclosure Date: April 14, 2023 (last updated October 08, 2023)
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
Attacker Value
Unknown

CVE-2023-29799

Disclosure Date: April 14, 2023 (last updated October 08, 2023)
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
Attacker Value
Unknown

CVE-2023-29798

Disclosure Date: April 14, 2023 (last updated October 08, 2023)
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.