T10
TOTOLINK- Software type
- —
- Catalog vulnerabilities
- 12
Severity across 12 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 12 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 12 vulnerability records affecting T10.
Among the 12 records analyzed by CyStack, 9 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2025-14964TOTOLINK T10 cstecgi.cgi sprintf stack-based overflow | Exploitation statusNot known exploited | FixNot confirmed | Published12/19/2025 | SeverityCritical |
CVE-2025-9533TOTOLINK T10 formLoginAuth.htm improper authentication | Exploitation statusPublic exploit | FixNot confirmed | Published08/27/2025 | SeverityMedium |
CVE-2025-6139TOTOLINK T10 shadow.sample hard-coded password | Exploitation statusPublic exploit | FixNot confirmed | Published06/16/2025 | SeverityLow |
CVE-2025-6138TOTOLINK T10 HTTP POST Request cstecgi.cgi setWizardCfg buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/16/2025 | SeverityHigh |
CVE-2025-6137TOTOLINK T10 HTTP POST Request cstecgi.cgi setWiFiScheduleCfg buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/16/2025 | SeverityHigh |
CVE-2025-5905TOTOLINK T10 POST Request cstecgi.cgi setWiFiRepeaterCfg buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/10/2025 | SeverityHigh |
CVE-2025-5904TOTOLINK T10 POST Request cstecgi.cgi setWiFiMeshName buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/10/2025 | SeverityHigh |
CVE-2025-5903TOTOLINK T10 POST Request cstecgi.cgi setWiFiAclRules buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/09/2025 | SeverityHigh |
CVE-2025-5902TOTOLINK T10 POST Request cstecgi.cgi setUpgradeFW buffer overflow | Exploitation statusPublic exploit | FixYes | Published06/09/2025 | SeverityHigh |
CVE-2025-5901TOTOLINK T10 POST Request cstecgi.cgi UploadCustomModule buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/09/2025 | SeverityHigh |
CVE-2025-4496TOTOLINK T10/A3100R/A950RG/A800R/N600R/A3000RU/A810R cstecgi.cgi CloudACMunualUpdate buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published05/10/2025 | SeverityHigh |
CVE-2024-9001TOTOLINK T10 cstecgi.cgi setTracerouteCfg os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published09/19/2024 | SeverityMedium |