CVE-2026-51669
- EPSS 0.36%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 13:19:43
Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51670
- EPSS 0.44%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 13:19:43
Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51671
- EPSS 0.36%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 13:19:43
Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51672
- EPSS 0.36%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 13:19:43
Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51673
- EPSS 0.33%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 13:19:44
Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51674
- EPSS 0.44%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 13:19:44
Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51675
- EPSS 0.36%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 13:19:44
Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51676
- EPSS 0.36%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 13:19:44
Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51677
- EPSS 0.29%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 13:19:44
Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51678
- EPSS 0.19%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 16:17:02
Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.