VYPR

T6

by Totolink

CVEs (178)

  • CVE-2026-51615HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2022-32053HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.

  • CVE-2022-32052HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_004137a4.

  • CVE-2022-32051HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc, week, sTime, eTime parameters in the function FUN_004133c4.

  • CVE-2022-32050HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.

  • CVE-2022-32049HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the url parameter in the function FUN_00418540.

  • CVE-2022-32048HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the command parameter in the function FUN_0041cc88.

  • CVE-2022-32047HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00412ef4.

  • CVE-2022-32046HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_0041880c.

  • CVE-2022-32045HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00413be4.

  • CVE-2022-32044HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the password parameter in the function FUN_00413f80.

  • CVE-2025-7525MedJul 13, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument command leads…

  • CVE-2025-7524MedJul 13, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ip leads to command…

  • CVE-2026-51756MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51748MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51742MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51739MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51714MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter roaming behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51712MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter wireless availability windows via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51703MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter when Wi-Fi is available via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Page 6 of 9