CVE-2026-51769
- EPSS 0.44%
- Veröffentlicht 01.09.2026 16:17:05
- Zuletzt bearbeitet 02.09.2026 19:17:20
Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51770
- EPSS 0.44%
- Veröffentlicht 01.09.2026 16:17:05
- Zuletzt bearbeitet 02.09.2026 18:19:59
Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker compone...
CVE-2026-51767
- EPSS 0.18%
- Veröffentlicht 01.09.2026 16:17:04
- Zuletzt bearbeitet 03.09.2026 18:17:22
Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51768
- EPSS 0.33%
- Veröffentlicht 01.09.2026 16:17:04
- Zuletzt bearbeitet 02.09.2026 17:17:44
Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the master device via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51741
- EPSS 0.18%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 18:17:21
Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51742
- EPSS 0.34%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 21:00:36
Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51743
- EPSS 0.36%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 21:00:36
Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51744
- EPSS 0.44%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 17:21:57
Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the ...
CVE-2026-51745
- EPSS 0.3%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 21:00:36
Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51747
- EPSS 0.18%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 18:17:21
Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a crafted MQTT message to the cs_broker component.