CVE-2026-51725
- EPSS 0.29%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:59:32
Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51726
- EPSS 0.36%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:18
Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51727
- EPSS 0.24%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 16:17:02
Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administrative import and export endpoint information via sending a crafted POST request to /cgi-bin/cstecgi.cgi...
CVE-2026-51728
- EPSS 0.16%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 02.09.2026 16:17:17
Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51729
- EPSS 0.29%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:18
Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51730
- EPSS 0.29%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:59:32
Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51731
- EPSS 0.36%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:18
Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51732
- EPSS 0.3%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 16:17:03
Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51733
- EPSS 0.18%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 02.09.2026 16:17:17
Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51734
- EPSS 0.44%
- Veröffentlicht 31.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 15:17:19
Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi.