📦 T10 Firmware

by Totolink

🔍 What is T10 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-44655

CRITICAL CVSS 9.8 Jul 21, 2025

This vulnerability in TOTOLink routers allows attackers to bypass FTP directory restrictions due to misconfigured vsftpd settings. Attackers can access system files, escalate privileges, or use the co...

CVE-2024-8162

CRITICAL CVSS 9.8 Aug 26, 2024

This critical vulnerability in TOTOLINK T10 AC1200 routers involves hard-coded credentials in the Telnet service configuration file, allowing remote attackers to gain unauthorized access. Attackers ca...

CVE-2022-25130

CRITICAL CVSS 9.8 Feb 19, 2022

This CVE describes a command injection vulnerability in TOTOLINK router firmware that allows attackers to execute arbitrary commands via crafted MQTT packets. Attackers can gain full control of affect...

CVE-2022-25132

CRITICAL CVSS 9.8 Feb 19, 2022

This is a critical command injection vulnerability in TOTOLINK T6 routers that allows attackers to execute arbitrary commands on affected devices by sending specially crafted MQTT packets. Attackers c...

CVE-2022-25136

CRITICAL CVSS 9.8 Feb 19, 2022

This CVE describes a command injection vulnerability in TOTOLINK router firmware that allows attackers to execute arbitrary commands via crafted MQTT packets. Attackers can gain full control of affect...

CVE-2025-6138

HIGH CVSS 8.8 Jun 16, 2025

A critical buffer overflow vulnerability in TOTOLINK T10 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the setWizardCfg function. This af...

CVE-2025-6137

HIGH CVSS 8.8 Jun 16, 2025

A critical buffer overflow vulnerability in TOTOLINK T10 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the setWiFiScheduleCfg function. T...

CVE-2025-5903

HIGH CVSS 8.8 Jun 10, 2025

A critical buffer overflow vulnerability in TOTOLINK T10 routers allows remote attackers to execute arbitrary code by sending specially crafted POST requests to the /cgi-bin/cstecgi.cgi endpoint. This...

CVE-2025-5905

HIGH CVSS 8.8 Jun 10, 2025

A critical buffer overflow vulnerability in TOTOLINK T10 routers allows remote attackers to execute arbitrary code by sending specially crafted POST requests to the setWiFiRepeaterCfg function. This a...

CVE-2025-5902

HIGH CVSS 8.8 Jun 9, 2025

This critical vulnerability in TOTOLINK T10 routers allows remote attackers to execute arbitrary code via a buffer overflow in the firmware upgrade function. Attackers can exploit this by sending spec...

CVE-2025-4496

HIGH CVSS 8.8 May 10, 2025

A critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by manipulating the FileName parameter in the CloudACMunualUpdate function. This affects ...

CVE-2024-8577

HIGH CVSS 8.8 Sep 8, 2024

This critical buffer overflow vulnerability in TOTOLINK AC1200 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the setStaticDhcpRules function. Attac...

CVE-2024-8573

HIGH CVSS 8.8 Sep 8, 2024

A critical buffer overflow vulnerability in TOTOLINK AC1200 routers allows remote attackers to execute arbitrary code by manipulating parameters in the setParentalRules function. This affects TOTOLINK...

CVE-2024-9001

MEDIUM CVSS 6.3 Sep 19, 2024

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK T10 routers by exploiting a command injection flaw in the setTracerouteCfg function. Atta...