CVE-2025-14964: Totolink t10 Firmware
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument loginAuthUrl leads to stack-based buffer overflow. The attack may be performed from remote.
Affected products
- Totolink t10 Firmware: version 4.1.8cu.5803_b20200521 only
Published 2025-12-19. Last modified 2026-06-17.