Totolink

    Dashboard / Vendors

    Products: 174
    Vulnerabilities: 1410
    Known Exploited: 0
    592
    Critical Level Threats
    499
    High Level Threats
    287
    Medium Level Threats
    29
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-85031

    TOTOLINK CP450 cstecgi.cgi buffer overflow

    Last Modified: Sep 03, 2026
    Published: Sep 03, 2026

    CVE-2026-51747

    Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a crafted MQTT message to the cs_broker component.

    Last Modified: Sep 03, 2026
    Published: Sep 01, 2026

    CVE-2026-51752

    Unauthenticated MQTT Access Enables Static Info Exfiltration in TOTOLINK T6

    Last Modified: Sep 02, 2026
    Published: Sep 01, 2026

    CVE-2026-51745

    Unauthenticated MQTT Message Refresh Primary Station List via Access Control Bypass

    Last Modified: Sep 01, 2026
    Published: Sep 01, 2026

    CVE-2026-51748

    Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.

    Last Modified: Sep 02, 2026
    Published: Sep 01, 2026
    Items Per Page