Vulnerability Description
A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | T10 Firmware | 4.1.8cu.5207_b20210320 |
| Totolink | T10 | 2.0 |
Related Weaknesses (CWE)
References
- https://candle-throne-f75.notion.site/TOTOLINK-T10-shadow-20ddf0aa118580f5a455cdExploitThird Party Advisory
- https://vuldb.com/?ctiid.312608Permissions RequiredVDB Entry
- https://vuldb.com/?id.312608Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.592922Third Party AdvisoryVDB Entry
- https://www.totolink.net/Product
FAQ
What is CVE-2025-6139?
CVE-2025-6139 is a vulnerability with a CVSS score of 3.9 (LOW). A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file /etc/shadow.sample. The manipulation...
How severe is CVE-2025-6139?
CVE-2025-6139 has been rated LOW with a CVSS base score of 3.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-6139?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink T10 Firmware, Totolink T10.