CVE-2026-51763
- EPSS 0.44%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 17:21:57
Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51764
- EPSS 0.44%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 17:21:57
Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51765
- EPSS 0.44%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 02.09.2026 18:19:59
Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51766
- EPSS 0.43%
- Veröffentlicht 01.09.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 21:00:36
Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the ...
CVE-2026-51719
- EPSS 0.26%
- Veröffentlicht 31.08.2026 16:18:37
- Zuletzt bearbeitet 01.09.2026 14:17:33
Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove URL filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51717
- EPSS 0.29%
- Veröffentlicht 31.08.2026 16:18:36
- Zuletzt bearbeitet 01.09.2026 14:17:32
Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51718
- EPSS 0.35%
- Veröffentlicht 31.08.2026 16:18:36
- Zuletzt bearbeitet 01.09.2026 14:17:32
Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51666
- EPSS 0.19%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 16:17:01
Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device initialization state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51667
- EPSS 0.19%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 16:17:01
Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51668
- EPSS 0.33%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 13:19:43
Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.