Total
7692 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-51634 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain core wireless settings, including SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51633 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain simplified guest Wi-Fi configuration, including guest credentials, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51632 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51631 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS runtime status via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51630 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS configuration, including domain, username, and password, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51629 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51614 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain access-device policy and client state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51613 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51610 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51663 | 2026-09-01 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51662 | 2026-09-01 | N/A | 7.5 HIGH | ||
| Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51661 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51654 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain schedule or scheduled-reboot configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51653 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain storage feature state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51652 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain UPnP enablement and parsed port-mapping information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51651 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Smart QoS configuration and rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51640 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getMeshNeighborTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh neighbor information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51639 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain AP-specific Wi-Fi scheduling rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51638 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the getWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain guest Wi-Fi configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51706 | 2026-09-01 | N/A | 4.3 MEDIUM | ||
| Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
