CVE-2025-6139

A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://candle-throne-f75.notion.site/TOTOLINK-T10-shadow-20ddf0aa118580f5a455cd5dbc521472 Exploit Third Party Advisory
https://vuldb.com/?ctiid.312608 Permissions Required VDB Entry
https://vuldb.com/?id.312608 Third Party Advisory VDB Entry
https://vuldb.com/?submit.592922 Third Party Advisory VDB Entry
https://www.totolink.net/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:t10_firmware:4.1.8cu.5207_b20210320:*:*:*:*:*:*:*
cpe:2.3:h:totolink:t10:2.0:*:*:*:*:*:*:*

History

26 Jun 2025, 16:27

Type Values Removed Values Added
References () https://candle-throne-f75.notion.site/TOTOLINK-T10-shadow-20ddf0aa118580f5a455cd5dbc521472 - () https://candle-throne-f75.notion.site/TOTOLINK-T10-shadow-20ddf0aa118580f5a455cd5dbc521472 - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.312608 - () https://vuldb.com/?ctiid.312608 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.312608 - () https://vuldb.com/?id.312608 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.592922 - () https://vuldb.com/?submit.592922 - Third Party Advisory, VDB Entry
References () https://www.totolink.net/ - () https://www.totolink.net/ - Product
References () https://candle-throne-f75.notion.site/TOTOLINK-T10-shadow-20ddf0aa118580f5a455cd5dbc521472 - () https://candle-throne-f75.notion.site/TOTOLINK-T10-shadow-20ddf0aa118580f5a455cd5dbc521472 - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.312608 - () https://vuldb.com/?ctiid.312608 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.312608 - () https://vuldb.com/?id.312608 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.592922 - () https://vuldb.com/?submit.592922 - Third Party Advisory, VDB Entry
References () https://www.totolink.net/ - () https://www.totolink.net/ - Product
CPE cpe:2.3:o:totolink:t10_firmware:4.1.8cu.5207_b20210320:*:*:*:*:*:*:*
cpe:2.3:h:totolink:t10:2.0:*:*:*:*:*:*:*
First Time Totolink t10
Totolink t10 Firmware
Totolink
CPE cpe:2.3:o:totolink:t10_firmware:4.1.8cu.5207_b20210320:*:*:*:*:*:*:*
cpe:2.3:h:totolink:t10:2.0:*:*:*:*:*:*:*
First Time Totolink t10
Totolink t10 Firmware
Totolink

17 Jun 2025, 20:50

Type Values Removed Values Added
CPE cpe:2.3:o:totolink:t10_firmware:4.1.8cu.5207_b20210320:*:*:*:*:*:*:*
cpe:2.3:h:totolink:t10:2.0:*:*:*:*:*:*:*
References () https://candle-throne-f75.notion.site/TOTOLINK-T10-shadow-20ddf0aa118580f5a455cd5dbc521472 - Exploit, Third Party Advisory () https://candle-throne-f75.notion.site/TOTOLINK-T10-shadow-20ddf0aa118580f5a455cd5dbc521472 -
References () https://vuldb.com/?ctiid.312608 - Permissions Required, VDB Entry () https://vuldb.com/?ctiid.312608 -
References () https://vuldb.com/?id.312608 - Third Party Advisory, VDB Entry () https://vuldb.com/?id.312608 -
References () https://vuldb.com/?submit.592922 - Third Party Advisory, VDB Entry () https://vuldb.com/?submit.592922 -
References () https://www.totolink.net/ - Product () https://www.totolink.net/ -

16 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-16 21:15

Updated : 2025-06-26 16:27


NVD link : CVE-2025-6139

Mitre link : CVE-2025-6139

CVE.ORG link : CVE-2025-6139


JSON object : View

Products Affected

totolink

  • t10
  • t10_firmware
CWE
CWE-255

Credentials Management Errors

CWE-259

Use of Hard-coded Password