CVE-2025-9533: TOTOLINK T10 formLoginAuth.htm improper authentication
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9533?
CVE-2025-9533 is considered a critical vulnerability due to its potential for remote exploitation leading to improper authentication.
How do I fix CVE-2025-9533?
To fix CVE-2025-9533, ensure you update the TOTOLINK T10 firmware to the latest version provided by the vendor.
What are the potential impacts of CVE-2025-9533?
The potential impacts of CVE-2025-9533 include unauthorized access to the device and manipulation of sensitive information.
Who is affected by CVE-2025-9533?
CVE-2025-9533 affects users of the TOTOLINK T10 router model specifically running firmware version 4.1.8cu.5241_B20210927.
How does CVE-2025-9533 exploit the vulnerability?
CVE-2025-9533 exploits the vulnerability by manipulating the authCode argument in the file /formLoginAuth.htm, allowing for improper authentication.