CVE-2026-51635
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 19:17:22
Incorrect access control in the getWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi scheduling rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51636
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:28
Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51637
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 19:17:23
Incorrect access control in the getMeshPortalTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh portal table information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51638
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 18:17:40
Incorrect access control in the getWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain guest Wi-Fi configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51639
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 18:17:40
Incorrect access control in the getApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain AP-specific Wi-Fi scheduling rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51640
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 18:17:41
Incorrect access control in the getMeshNeighborTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh neighbor information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51641
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:28
Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51642
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 16:16:58
Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh routing information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51643
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 16:16:59
Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain NTP configuration and current time data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51644
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 16:16:59
Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.