VendorsTOTOLINKt10all versions
Vulnerabilities

TOTOLINK T10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2024-8162
TOTOLINK T10 AC1200 Telnet Service product.ini hard-coded credentials
Published 2024-08-26 · Analyzed
10.0EPSS 0.017
CVE-2025-14964
TOTOLINK T10 cstecgi.cgi sprintf stack-based overflow
Published 2025-12-19 · Analyzed
10.0EPSS 0.010
CVE-2025-9533
TOTOLINK T10 formLoginAuth.htm improper authentication
Published 2025-08-27 · Analyzed
9.8EPSS 0.094
CVE-2022-25132
A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.029
CVE-2022-25131
A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2022-25136
A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2022-25137
A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2022-25130
A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2025-4496
TOTOLINK T10/A3100R/A950RG/A800R/N600R/A3000RU/A810R cstecgi.cgi CloudACMunualUpdate buffer overflow
Published 2025-05-10 · Analyzed
9.8EPSS 0.012
CVE-2025-44655
In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.
Published 2025-07-21 · Modified
9.8EPSS 0.003
CVE-2025-5905
TOTOLINK T10 POST Request cstecgi.cgi setWiFiRepeaterCfg buffer overflow
Published 2025-06-10 · Analyzed
9.0EPSS 0.113
CVE-2025-5903
TOTOLINK T10 POST Request cstecgi.cgi setWiFiAclRules buffer overflow
Published 2025-06-09 · Analyzed
9.0EPSS 0.110
CVE-2025-5904
TOTOLINK T10 POST Request cstecgi.cgi setWiFiMeshName buffer overflow
Published 2025-06-10 · Analyzed
9.0EPSS 0.110
CVE-2025-5901
TOTOLINK T10 POST Request cstecgi.cgi UploadCustomModule buffer overflow
Published 2025-06-09 · Analyzed
9.0EPSS 0.062
CVE-2025-5902
TOTOLINK T10 POST Request cstecgi.cgi setUpgradeFW buffer overflow
Published 2025-06-09 · Analyzed
9.0EPSS 0.059
CVE-2024-8573
TOTOLINK AC1200 T8/AC1200 T10 cstecgi.cgi setParentalRules buffer overflow
Published 2024-09-08 · Modified
9.0EPSS 0.014
CVE-2024-8577
TOTOLINK AC1200 T8/AC1200 T10 cstecgi.cgi setStaticDhcpRules buffer overflow
Published 2024-09-08 · Analyzed
9.0EPSS 0.011
CVE-2024-8576
TOTOLINK AC1200 T8/AC1200 T10 cstecgi.cgi setIpPortFilterRules buffer overflow
Published 2024-09-08 · Analyzed
9.0EPSS 0.011
CVE-2025-6138
TOTOLINK T10 HTTP POST Request cstecgi.cgi setWizardCfg buffer overflow
Published 2025-06-16 · Analyzed
9.0EPSS 0.010
CVE-2025-6137
TOTOLINK T10 HTTP POST Request cstecgi.cgi setWiFiScheduleCfg buffer overflow
Published 2025-06-16 · Analyzed
9.0EPSS 0.010
CVE-2024-9001
TOTOLINK T10 cstecgi.cgi setTracerouteCfg os command injection
Published 2024-09-19 · Analyzed
8.8EPSS 0.033
CVE-2025-6139
TOTOLINK T10 shadow.sample hard-coded password
Published 2025-06-16 · Analyzed
3.9EPSS 0.004