CVE-2026-51691
- EPSS 0.18%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 02.09.2026 16:17:16
Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51692
- EPSS 0.16%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 02.09.2026 16:17:16
Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51693
- EPSS 0.35%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:15
Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51694
- EPSS 0.26%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:15
Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51695
- EPSS 0.26%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:15
Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter dynamic DNS state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51696
- EPSS 0.35%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:16
Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51697
- EPSS 0.29%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:16
Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51698
- EPSS 0.36%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:16
Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51699
- EPSS 0.44%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:16
Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51700
- EPSS 0.36%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:17
Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.