CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2026-51722

    Last Modified: 2 Sept 2026

    Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51718

    Last Modified: 1 Sept 2026

    Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51720

    Last Modified: 31 Aug 2026

    Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51713

    Last Modified: 2 Sept 2026

    Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    5.9
    Medium

    CVE-2026-51714

    Last Modified: 2 Sept 2026

    Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter roaming behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    5.9
    Medium

    CVE-2026-51712

    Last Modified: 2 Sept 2026

    Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter wireless availability windows via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51711

    Last Modified: 1 Sept 2026

    Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51710

    Last Modified: 1 Sept 2026

    Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51705

    Last Modified: 3 Sept 2026

    Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    4.3
    Medium

    CVE-2026-51704

    Last Modified: 2 Sept 2026

    Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter mesh configurations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51700

    Last Modified: 2 Sept 2026

    Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    4.3
    Medium

    CVE-2026-51702

    Last Modified: 2 Sept 2026

    Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter firewall policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51692

    Last Modified: 3 Sept 2026

    Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51693

    Last Modified: 2 Sept 2026

    Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51691

    Last Modified: 3 Sept 2026

    Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51689

    Last Modified: 3 Sept 2026

    Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51687

    Last Modified: 3 Sept 2026

    Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51677

    Last Modified: 1 Sept 2026

    Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51675

    Last Modified: 1 Sept 2026

    Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    4.3
    Medium

    CVE-2026-51667

    Last Modified: 2 Sept 2026

    Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    7.5
    High

    CVE-2026-51673

    Last Modified: 1 Sept 2026

    Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    7.5
    High

    CVE-2026-17615

    Last Modified: 11 Sept 2026

    A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51686

    Last Modified: 3 Sept 2026

    Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    7.5
    High

    CVE-2026-51688

    Last Modified: 3 Sept 2026

    Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS) via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    4.3
    Medium

    CVE-2026-51683

    Last Modified: 2 Sept 2026

    Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN network configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51680

    Last Modified: 31 Aug 2026

    Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51681

    Last Modified: 31 Aug 2026

    Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51725

    Last Modified: 31 Aug 2026

    Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51669

    Last Modified: 1 Sept 2026

    Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    7.5
    High

    CVE-2026-51671

    Last Modified: 1 Sept 2026

    Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51674

    Last Modified: 1 Sept 2026

    Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51701

    Last Modified: 1 Sept 2026

    Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51708

    Last Modified: 1 Sept 2026

    Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51709

    Last Modified: 1 Sept 2026

    Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51717

    Last Modified: 1 Sept 2026

    Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    7.5
    High

    CVE-2026-51719

    Last Modified: 1 Sept 2026

    Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove URL filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51740

    Last Modified: 1 Sept 2026

    Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51698

    Last Modified: 2 Sept 2026

    Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51699

    Last Modified: 2 Sept 2026

    Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    4.3
    Medium

    CVE-2026-51706

    Last Modified: 2 Sept 2026

    Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51721

    Last Modified: 2 Sept 2026

    Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51724

    Last Modified: 2 Sept 2026

    Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    5.3
    Medium

    CVE-2026-51737

    Last Modified: 2 Sept 2026

    Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-79408

    Last Modified: 2 Sept 2026

    An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.

    Published: 31 Aug 2026
    7.5
    High

    CVE-2026-51694

    Last Modified: 2 Sept 2026

    Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51696

    Last Modified: 2 Sept 2026

    Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51697

    Last Modified: 2 Sept 2026

    Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51715

    Last Modified: 2 Sept 2026

    Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.1
    Critical

    CVE-2026-51729

    Last Modified: 2 Sept 2026

    Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-51734

    Last Modified: 2 Sept 2026

    Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

    Published: 31 Aug 2026