Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

TOTOLINK T10 Hard-Coded Password Vulnerability in Shadow Sample File

Vulnerability

A vulnerability exists in the TOTOLINK T10 router running firmware version 4.1.8cu.5207. The issue arises from an unknown functionality in the file /etc/shadow.sample, where a hard-coded password is utilized. This vulnerability can only be exploited within the local network, and requires additional authentication. The exploitation is considered difficult, but a public proof-of-concept exploit is available.

Impact

The vulnerability introduces a hard-coded password, which can be exploited for unauthorized access or actions, potentially leading to a compromise of the device's functionality or security.

Added: Jun 16, 2025, 9:17 PM
Updated: Jun 16, 2025, 9:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.0
remediation
0.0
relevance
0.2
threat
8.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.