CVE-2026-51679
- EPSS 0.35%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:59:32
Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51680
- EPSS 0.29%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:59:32
Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51681
- EPSS 0.29%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:59:32
Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51683
- EPSS 0.2%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 17:17:30
Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN network configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51684
- EPSS 0.18%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 02.09.2026 16:17:15
Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51686
- EPSS 0.18%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 18:17:21
Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51687
- EPSS 0.18%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 02.09.2026 16:17:15
Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51688
- EPSS 0.18%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 02.09.2026 16:17:16
Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS) via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51689
- EPSS 0.18%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 02.09.2026 16:17:16
Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51690
- EPSS 0.18%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 02.09.2026 16:17:16
Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi.