Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42400
Total
3455
Critical
12534
High
12466
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-51647 | UNKNOWN | — | Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a … | Aug 28, 2026 |
| CVE-2026-51646 | UNKNOWN | — | Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain parental-control rules via sending a crafted POST request to … | Aug 28, 2026 |
| CVE-2026-51645 | UNKNOWN | — | Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the administrative username via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51644 | UNKNOWN | — | Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a … | Aug 28, 2026 |
| CVE-2026-51643 | UNKNOWN | — | Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain NTP configuration and current time data via sending a … | Aug 28, 2026 |
| CVE-2026-51642 | UNKNOWN | — | Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh routing information via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51641 | UNKNOWN | — | Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a … | Aug 28, 2026 |
| CVE-2026-51640 | UNKNOWN | — | Incorrect access control in the getMeshNeighborTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh neighbor information via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51639 | UNKNOWN | — | Incorrect access control in the getApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain AP-specific Wi-Fi scheduling rules via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51638 | UNKNOWN | — | Incorrect access control in the getWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain guest Wi-Fi configuration information via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51637 | UNKNOWN | — | Incorrect access control in the getMeshPortalTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh portal table information via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51636 | UNKNOWN | — | Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51635 | UNKNOWN | — | Incorrect access control in the getWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi scheduling rules via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51634 | UNKNOWN | — | Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain core wireless settings, including SSIDs and Wi-Fi keys, via … | Aug 28, 2026 |
| CVE-2026-51633 | UNKNOWN | — | Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain simplified guest Wi-Fi configuration, including guest credentials, via sending … | Aug 28, 2026 |
| CVE-2026-51632 | UNKNOWN | — | Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51631 | UNKNOWN | — | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS runtime status via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51630 | UNKNOWN | — | Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS configuration, including domain, username, and password, via sending … | Aug 28, 2026 |
| CVE-2026-51629 | UNKNOWN | — | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51628 | UNKNOWN | — | Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a … | Aug 28, 2026 |
| CVE-2026-51627 | UNKNOWN | — | Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted … | Aug 28, 2026 |
| CVE-2026-51626 | UNKNOWN | — | Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a … | Aug 28, 2026 |
| CVE-2026-51625 | UNKNOWN | — | Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via … | Aug 28, 2026 |
| CVE-2026-51624 | UNKNOWN | — | Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51623 | UNKNOWN | — | Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending … | Aug 28, 2026 |