VYPR

T6

by Totolink

CVEs (178)

  • CVE-2023-7223MedJan 9, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input showSyslog leads to improper access controls. It is possible to…

  • CVE-2026-51761MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51752MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51745MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51737MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51732MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51727MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administrative import and export endpoint information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51706MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51704MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter mesh configurations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51702MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter firewall policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51683MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN network configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51678MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51667MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51666MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device initialization state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51665MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain traceroute diagnostic logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51664MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51656MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain VPN pass-through and WAN ping filter settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51655MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51654MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain schedule or scheduled-reboot configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51653MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain storage feature state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Page 7 of 9