VYPR

totolink

by Totolink

CVEs (2)

  • CVE-2026-51718CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2015-9551CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface via the formSysCmd sysCmd parameter.