VYPR

T6

by Totolink

CVEs (178)

  • CVE-2026-51668HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51662HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51659HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51658HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51650HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain remote-management enablement and port information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51648HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN information returned by the endpoint via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51647HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51644HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51642HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh routing information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51641HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51627HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51625HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51624HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51623HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51621HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51620HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51619HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51618HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51617HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, encryption keys, and connected…

  • CVE-2026-51616HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Page 5 of 9