VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 315 of 406
  • CVE-2026-71807MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission annotations, and the Service layer does not verify whether the current user is the task handler/related user. Authenticated low-privileged remote attackers can…

  • CVE-2026-75167MedSep 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to change the password of arbitrary accounts.

  • CVE-2026-84804MedSep 2, 2026
    risk 0.28cvss 5.4epss 0.00

    Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission can revoke team access without the required permissions_activity check, bypassing…

  • CVE-2026-73741MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation could allow an attacker to access limited data beyond what is authorized by the user's existing privilege…

  • CVE-2026-82809MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in vidIQ Vision for YouTube Extension 3.199.0 on Chrome. The affected element is the function window.addEventListener of the component postMessage Handler. Performing a manipulation of the argument vidiqEvent results in information disclosure.…

  • CVE-2026-51706MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51704MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter mesh configurations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51702MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter firewall policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51683MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN network configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51678MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51667MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51666MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device initialization state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51665MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain traceroute diagnostic logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51664MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51656MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain VPN pass-through and WAN ping filter settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51655MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51654MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain schedule or scheduled-reboot configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51653MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain storage feature state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51652MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain UPnP enablement and parsed port-mapping information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51651MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Smart QoS configuration and rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.