Totolink

T6

165 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:23

Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter wireless availability windows via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.29%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 15:17:17

Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.27%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:23

Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter roaming behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.35%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 15:17:17

Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.26%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 14:17:31

Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.29%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 31.08.2026 20:59:32

Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.29%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 15:17:17

Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.29%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 15:17:18

Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cg...

  • EPSS 0.16%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 02.09.2026 16:17:16

Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.35%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 15:17:18

Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.