CVE-2023-29801
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
14/04/2023
Last modified:
06/02/2025
Description
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:totolink:x18_firmware:9.1.0cu.2024_b20220329:*:*:*:*:*:*:* | ||
| cpe:2.3:h:totolink:x18:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



