Total
397453 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-51736 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51734 | 2026-09-01 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51731 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51729 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51726 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51724 | 2026-09-01 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51722 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51721 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51715 | 2026-09-01 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51713 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51700 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51699 | 2026-09-01 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51698 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51697 | 2026-09-01 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51696 | 2026-09-01 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51695 | 2026-09-01 | N/A | 7.5 HIGH | ||
| Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter dynamic DNS state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51694 | 2026-09-01 | N/A | 7.5 HIGH | ||
| Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51693 | 2026-09-01 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-44604 | 2026-09-01 | N/A | 7.0 HIGH | ||
| A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction. | |||||
| CVE-2026-28191 | 2026-09-01 | N/A | 8.8 HIGH | ||
| Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allows Privilege Escalation. This issue affects The Grid: from n/a through 2.8.0. | |||||
