Totolink

T6

165 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 31.08.2026 20:59:32

Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.36%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 15:17:18

Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.24%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 16:17:02

Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administrative import and export endpoint information via sending a crafted POST request to /cgi-bin/cstecgi.cgi...

  • EPSS 0.16%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 02.09.2026 16:17:17

Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.29%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 15:17:18

Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.29%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 31.08.2026 20:59:32

Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.36%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 15:17:18

Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.3%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 16:17:03

Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 02.09.2026 16:17:17

Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.44%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 15:17:19

Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi.