Totolink

T6

165 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 17:17:27

Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 17:17:27

Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 17:17:27

Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 17:17:27

Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:21

Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:22

Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS configuration, including domain, username, and password, via sending a crafted POST request to /cgi-bin/cstecgi.c...

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:22

Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS runtime status via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:22

Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:22

Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain simplified guest Wi-Fi configuration, including guest credentials, via sending a crafted POST request to /cgi...

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:22

Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain core wireless settings, including SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cg...