CVE-2025-9533
7.3TOTOLINK · T10
TOTOLINK T10 contains an improper authentication vulnerability in the /formLoginAuth.htm endpoint, allowing remote attackers to bypass authentication via the authCode parameter.
Executive summary
An improper authentication vulnerability in TOTOLINK T10 routers permits remote, unauthenticated attackers to bypass security controls, posing a significant risk to device integrity.
Vulnerability
The flaw exists in the /formLoginAuth.htm file, where the authCode parameter is improperly validated. This allows an unauthenticated remote attacker to manipulate the authentication process.
Business impact
The vulnerability carries a CVSS score of 7.3, indicating a high severity risk. Successful exploitation could allow unauthorized parties to gain administrative access to networking hardware, potentially leading to unauthorized network traffic interception, configuration changes, or the facilitation of further attacks against internal systems connected to the router.
Remediation
Immediate Action: Since no official patch is currently identified, administrators should restrict access to the device management interface to trusted internal IP addresses only. Disable remote management features if they are not strictly necessary for business operations.
Proactive Monitoring: Monitor network traffic for unusual requests directed at the /formLoginAuth.htm endpoint. Review system logs for unauthorized login attempts or unexpected configuration modifications.
Compensating Controls: Deploy a Web Application Firewall or similar network security appliance to filter inbound requests and block traffic attempting to manipulate authentication parameters on the router interface.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the researcher write-up at the provided GitHub repository.
Analyst recommendation
Given the confirmed existence of a public proof-of-concept and the high severity of authentication bypass, this vulnerability must be treated with urgency. Administrators should immediately isolate affected devices from public-facing exposure and monitor for any anomalous activity until the vendor provides a permanent firmware update.
More TOTOLINK CVEs
Sources
Originally found and disclosed by aLtEr (VulDB User), per the CVE Program record.
- VDB-321552 | TOTOLINK T10 formLoginAuth.htm improper authentication Vulnerability database entry
- VDB-321552 | CTI Indicators (IOB, IOC, IOA)
- Submit #635941 | TOTOLINK T10 T10_V4.1.8cu.5241_B20210927 Missing Authentication Third-party advisory
- Exploit / PoC
- totolink.net