VYPR

T6

by Totolink

CVEs (178)

  • CVE-2026-51731CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51730CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51729CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51726CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51725CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51722CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51720CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51717CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51711CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51710CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51701CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51681CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51680CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51679CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51677CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51676CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51675CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51672CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51669CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51661CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Page 3 of 9