Description
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument loginAuthUrl leads to stack-based buffer overflow. The attack may be performed from remote.
Problem types
Product status
Timeline
| 2025-12-19: | Advisory disclosed |
| 2025-12-19: | VulDB entry created |
| 2025-12-19: | VulDB entry last update |
Credits
JackWesley (VulDB User)
References
vuldb.com/?id.337599 (VDB-337599 | TOTOLINK T10 cstecgi.cgi sprintf stack-based overflow)
vuldb.com/?ctiid.337599 (VDB-337599 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.717720 (Submit #717720 | TOTOLINK T10 V2_Firmware V4.1.8cu.5083_B20200521 Buffer Overflow)
github.com/JackWesleyy/CVE/blob/main/TOTOLINK_T10_BOC.md
www.totolink.net/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.