Totolink

T6

165 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 03.09.2026 17:21:57

Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component.

  • EPSS 0.44%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 03.09.2026 17:21:57

Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the cs_broker component.

  • EPSS 0.44%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 02.09.2026 18:19:59

Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component.

  • EPSS 0.43%
  • Veröffentlicht 01.09.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 21:00:36

Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the ...

  • EPSS 0.26%
  • Veröffentlicht 31.08.2026 16:18:37
  • Zuletzt bearbeitet 01.09.2026 14:17:33

Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove URL filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.29%
  • Veröffentlicht 31.08.2026 16:18:36
  • Zuletzt bearbeitet 01.09.2026 14:17:32

Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.35%
  • Veröffentlicht 31.08.2026 16:18:36
  • Zuletzt bearbeitet 01.09.2026 14:17:32

Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.19%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 16:17:01

Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device initialization state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.19%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 16:17:01

Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.33%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 13:19:43

Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.