CVE-2026-51748
- EPSS 0.34%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 21:00:36
Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51750
- EPSS 0.44%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 17:21:57
Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51751
- EPSS 0.44%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 17:21:57
Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via sending a crafted MQTT message ...
CVE-2026-51752
- EPSS 0.3%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 21:00:36
Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker compone...
CVE-2026-51754
- EPSS 0.17%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 18:17:22
Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51756
- EPSS 0.34%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 21:00:36
Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51757
- EPSS 0.44%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 17:21:57
Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted MQTT message to the cs_broker comp...
CVE-2026-51760
- EPSS 0.44%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 17:21:57
Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51761
- EPSS 0.3%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 21:00:36
Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51762
- EPSS 0.18%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 18:17:22
Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to ...