CVE-2026-51615
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:25
Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51616
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:26
Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51617
- EPSS 0.12%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:26
Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, e...
CVE-2026-51618
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:26
Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51619
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:26
Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51620
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:26
Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi...
CVE-2026-51621
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:26
Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51622
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:27
Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51623
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:27
Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51624
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:27
Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi.