CVE-2026-51655
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:29
Incorrect access control in the getMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51656
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:29
Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain VPN pass-through and WAN ping filter settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51657
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:29
Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain syslog-related configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51658
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:29
Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51659
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:29
Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51660
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:30
Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51661
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 18:17:42
Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51662
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 18:17:42
Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51663
- EPSS 0.18%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 18:17:42
Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51664
- EPSS 0.17%
- Veröffentlicht 28.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 16:17:00
Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.