A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable leads to os command injection.
This vulnerability is handled as CVE-2024-10966. The attack may be launched remotely. Furthermore, there is an exploit available.