Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42683
Total
3463
Critical
12701
High
12563
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-51655 | UNKNOWN | — | Incorrect access control in the getMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain MAC filter rules via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51654 | UNKNOWN | — | Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain schedule or scheduled-reboot configuration information via sending a crafted … | Aug 28, 2026 |
| CVE-2026-51653 | UNKNOWN | — | Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain storage feature state information via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51652 | UNKNOWN | — | Incorrect access control in the getUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain UPnP enablement and parsed port-mapping information via sending a … | Aug 28, 2026 |
| CVE-2026-51651 | UNKNOWN | — | Incorrect access control in the getSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Smart QoS configuration and rules via sending a crafted … | Aug 28, 2026 |
| CVE-2026-51650 | UNKNOWN | — | Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain remote-management enablement and port information via sending a crafted … | Aug 28, 2026 |
| CVE-2026-51649 | UNKNOWN | — | Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a … | Aug 28, 2026 |
| CVE-2026-51648 | UNKNOWN | — | Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN information returned by the endpoint via sending a … | Aug 28, 2026 |
| CVE-2026-51647 | UNKNOWN | — | Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a … | Aug 28, 2026 |
| CVE-2026-51646 | UNKNOWN | — | Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain parental-control rules via sending a crafted POST request to … | Aug 28, 2026 |
| CVE-2026-51645 | UNKNOWN | — | Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the administrative username via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51644 | UNKNOWN | — | Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a … | Aug 28, 2026 |
| CVE-2026-51643 | UNKNOWN | — | Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain NTP configuration and current time data via sending a … | Aug 28, 2026 |
| CVE-2026-51642 | UNKNOWN | — | Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh routing information via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51641 | UNKNOWN | — | Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a … | Aug 28, 2026 |
| CVE-2026-51640 | UNKNOWN | — | Incorrect access control in the getMeshNeighborTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh neighbor information via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51639 | UNKNOWN | — | Incorrect access control in the getApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain AP-specific Wi-Fi scheduling rules via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51638 | UNKNOWN | — | Incorrect access control in the getWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain guest Wi-Fi configuration information via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51637 | UNKNOWN | — | Incorrect access control in the getMeshPortalTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh portal table information via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51636 | UNKNOWN | — | Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51635 | UNKNOWN | — | Incorrect access control in the getWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi scheduling rules via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51634 | UNKNOWN | — | Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain core wireless settings, including SSIDs and Wi-Fi keys, via … | Aug 28, 2026 |
| CVE-2026-51633 | UNKNOWN | — | Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain simplified guest Wi-Fi configuration, including guest credentials, via sending … | Aug 28, 2026 |
| CVE-2026-51632 | UNKNOWN | — | Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51631 | UNKNOWN | — | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS runtime status via sending a crafted POST request … | Aug 28, 2026 |