A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/aLtEr6/MY_test/blob/main/TOTOLINK/TOTOLINK%20T10%20Vulnerability.md | Broken Link |
| https://vuldb.com/?ctiid.321552 | Permissions Required VDB Entry |
| https://vuldb.com/?id.321552 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.635941 | Third Party Advisory VDB Entry |
| https://www.totolink.net/ | Product |
| https://github.com/aLtEr6/MY_test/blob/main/TOTOLINK/TOTOLINK%20T10%20Vulnerability.md | Broken Link |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-08-27 15:15
Updated : 2025-09-03 16:17
NVD link : CVE-2025-9533
Mitre link : CVE-2025-9533
CVE.ORG link : CVE-2025-9533
JSON object : View
Products Affected
totolink
- t10_firmware
- t10
CWE
CWE-287
Improper Authentication
