CVE-2026-51645
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:28
Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the administrative username via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51646
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:28
Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51647
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:28
Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51648
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:28
Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN information returned by the endpoint via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51649
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:29
Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51650
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:29
Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain remote-management enablement and port information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51651
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 18:17:41
Incorrect access control in the getSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Smart QoS configuration and rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51652
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 18:17:41
Incorrect access control in the getUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain UPnP enablement and parsed port-mapping information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51653
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 18:17:41
Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain storage feature state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51654
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 18:17:41
Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain schedule or scheduled-reboot configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.