CVE-2026-51712
- EPSS 0.27%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 19:17:23
Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter wireless availability windows via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51713
- EPSS 0.29%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:17
Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51714
- EPSS 0.27%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 19:17:23
Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter roaming behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51715
- EPSS 0.35%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:17
Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51716
- EPSS 0.26%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 14:17:31
Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51720
- EPSS 0.29%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:59:32
Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51721
- EPSS 0.29%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:17
Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51722
- EPSS 0.29%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:18
Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cg...
CVE-2026-51723
- EPSS 0.16%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 02.09.2026 16:17:16
Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51724
- EPSS 0.35%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:18
Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.