Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2025-29064
An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.018
EPSS Ranking
81.9%
CVSS Severity
CVSS v3 Score
9.8
References
https://github.com/kn0sky/cve/blob/main/TOTOLINK%20X18/OS%20Command%20Injection%20setLanguageCfg_lang.md
https://github.com/kn0sky/cve/blob/main/TOTOLINK%20X18/OS%20Command%20Injection%20setLanguageCfg_lang.md
Products affected by CVE-2025-29064
Totolink
»
X18
»
Version:
N/A
cpe:2.3:h:totolink:x18:-
Totolink
»
X18 Firmware
»
Version:
9.1.0cu.2024_b20220329
cpe:2.3:o:totolink:x18_firmware:9.1.0cu.2024_b20220329
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved