VYPR

CVEs

383,069 total · page 321 of 7,662

  • CVE-2026-51656MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain VPN pass-through and WAN ping filter settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51655MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51654MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain schedule or scheduled-reboot configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51653MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain storage feature state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51652MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain UPnP enablement and parsed port-mapping information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51651MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Smart QoS configuration and rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51650HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain remote-management enablement and port information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51649CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51648HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN information returned by the endpoint via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51647HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51646CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51645CriAug 28, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the administrative username via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51644HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51643CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain NTP configuration and current time data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51642HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh routing information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51641HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51640MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getMeshNeighborTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh neighbor information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51639MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain AP-specific Wi-Fi scheduling rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51638MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain guest Wi-Fi configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51637MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getMeshPortalTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh portal table information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51636CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51635MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi scheduling rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51634MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain core wireless settings, including SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51633MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain simplified guest Wi-Fi configuration, including guest credentials, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51632MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51631MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS runtime status via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51630MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS configuration, including domain, username, and password, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51629MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51628CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51627HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51626CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51625HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51624HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51623HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51622CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51621HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51620HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51619HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51618HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51617HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, encryption keys, and connected…

  • CVE-2026-51616HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51615HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51614MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain access-device policy and client state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51613MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51611CriAug 28, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message.

  • CVE-2026-51610MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51376MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh gossip cache

  • CVE-2026-50980MedAug 28, 2026
    risk 0.40cvss 6.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record

  • CVE-2026-39071MedAug 28, 2026
    risk 0.35cvss 5.4epss 0.00

    WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account.

  • CVE-2026-39070MedAug 28, 2026
    risk 0.31cvss 4.8epss 0.00

    WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit this to redirect user to malicious site or control the account.