CVE-2025-9533

7.3

TOTOLINK · T10

TOTOLINK T10 contains an improper authentication vulnerability in the /formLoginAuth.htm endpoint, allowing remote attackers to bypass authentication via the authCode parameter.

Executive summary

An improper authentication vulnerability in TOTOLINK T10 routers permits remote, unauthenticated attackers to bypass security controls, posing a significant risk to device integrity.

Vulnerability

The flaw exists in the /formLoginAuth.htm file, where the authCode parameter is improperly validated. This allows an unauthenticated remote attacker to manipulate the authentication process.

Business impact

The vulnerability carries a CVSS score of 7.3, indicating a high severity risk. Successful exploitation could allow unauthorized parties to gain administrative access to networking hardware, potentially leading to unauthorized network traffic interception, configuration changes, or the facilitation of further attacks against internal systems connected to the router.

Remediation

Immediate Action: Since no official patch is currently identified, administrators should restrict access to the device management interface to trusted internal IP addresses only. Disable remote management features if they are not strictly necessary for business operations.

Proactive Monitoring: Monitor network traffic for unusual requests directed at the /formLoginAuth.htm endpoint. Review system logs for unauthorized login attempts or unexpected configuration modifications.

Compensating Controls: Deploy a Web Application Firewall or similar network security appliance to filter inbound requests and block traffic attempting to manipulate authentication parameters on the router interface.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the researcher write-up at the provided GitHub repository.

Analyst recommendation

Given the confirmed existence of a public proof-of-concept and the high severity of authentication bypass, this vulnerability must be treated with urgency. Administrators should immediately isolate affected devices from public-facing exposure and monitor for any anomalous activity until the vendor provides a permanent firmware update.

More TOTOLINK CVEs

Sources

Originally found and disclosed by aLtEr (VulDB User), per the CVE Program record.