Totolink

T6

165 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 21:00:36

Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.

  • EPSS 0.44%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 03.09.2026 17:21:57

Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the cs_broker component.

  • EPSS 0.44%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 03.09.2026 17:21:57

Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via sending a crafted MQTT message ...

  • EPSS 0.3%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 21:00:36

Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker compone...

  • EPSS 0.17%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 03.09.2026 18:17:22

Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT message to the cs_broker component.

  • EPSS 0.34%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 21:00:36

Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.

  • EPSS 0.44%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 03.09.2026 17:21:57

Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted MQTT message to the cs_broker comp...

  • EPSS 0.44%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 03.09.2026 17:21:57

Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT message to the cs_broker component.

  • EPSS 0.3%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 21:00:36

Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.

  • EPSS 0.18%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 03.09.2026 18:17:22

Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to ...