Totolink
Totolink T6 Firmware: vulnerabilidades y CVE
Totolink T6 Firmware tiene 39 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses0
Críticas14
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-8170 | Alta (7.4) | 1.1% | — | 25 jul 2025 | A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748_B20211015. This vulnerability affects the function tcpcheck_net of the file /router/meshSlaveDlfw of the component MQTT Packet Handler. The… |
| CVE-2025-7952 | Baja (2.1) | 21% | — | 22 jul 2025 | A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. This vulnerability affects the function ckeckKeepAlive of the file wireless.so of the component MQTT Packet Handler. The manipulation leads to… |
| CVE-2025-7913 | Alta (7.4) | 0.85% | — | 21 jul 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the function updateWifiInfo of the component MQTT Service. The manipulation of the argument serverIp leads… |
| CVE-2025-7912 | Alta (7.4) | 1.1% | — | 20 jul 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affects the function recvSlaveUpgstatus of the component MQTT Service. The manipulation of the argument… |
| CVE-2025-7862 | Media (5.5) | 1.1% | — | 20 jul 2025 | A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component Telnet… |
| CVE-2025-7837 | Alta (7.4) | 1.1% | — | 19 jul 2025 | A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this issue is the function recvSlaveStaInfo of the component MQTT Service. The manipulation of the argument dest… |
| CVE-2025-7758 | Alta (7.4) | 0.85% | — | 17 jul 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748_B20211015. Affected by this issue is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP… |
| CVE-2025-7615 | Baja (2.1) | 2.4% | — | 14 jul 2025 | A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. Affected by this vulnerability is the function clearPairCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The… |
| CVE-2025-7614 | Baja (2.1) | 2.4% | — | 14 jul 2025 | A vulnerability classified as critical has been found in TOTOLINK T6 4.1.5cu.748. Affected is the function delDevice of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the… |
| CVE-2025-7613 | Baja (2.1) | 2.4% | — | 14 jul 2025 | A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been rated as critical. This issue affects the function CloudSrvVersionCheck of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The… |
| CVE-2025-7525 | Baja (2.1) | 2.9% | — | 13 jul 2025 | A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST… |
| CVE-2025-7524 | Baja (2.1) | 2.9% | — | 13 jul 2025 | A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler.… |
| CVE-2025-7460 | Alta (7.4) | 0.89% | — | 11 jul 2025 | A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component HTTP POST… |
| CVE-2025-6916 | Alta (7.4) | 0.89% | — | 30 jun 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of the argument authCode/goURL… |
| CVE-2023-7223 | Media (6.5) | 0.64% | — | 9 ene 2024 | A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input… |
| CVE-2023-7221 | Crítica (9.8) | 1.5% | — | 9 ene 2024 | A vulnerability was found in Totolink T6 4.1.9cu.5241_B20210923. It has been classified as critical. This affects the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request… |
| CVE-2022-38828 | Crítica (9.8) | 20% | — | 16 sept 2022 | TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi |
| CVE-2022-38827 | Crítica (9.8) | 13% | — | 16 sept 2022 | TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi |
| CVE-2022-38826 | Crítica (9.8) | 1.3% | — | 16 sept 2022 | In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi. |
| CVE-2022-38823 | Crítica (9.8) | 1.1% | — | 16 sept 2022 | In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample. |
| CVE-2022-32053 | Alta (7.5) | 1.1% | — | 1 jul 2022 | TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c. |
| CVE-2022-32052 | Alta (7.5) | 1.1% | — | 1 jul 2022 | TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_004137a4. |
| CVE-2022-32051 | Alta (7.5) | 1.1% | — | 1 jul 2022 | TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc, week, sTime, eTime parameters in the function FUN_004133c4. |
| CVE-2022-32050 | Alta (7.5) | 1.1% | — | 1 jul 2022 | TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40. |
| CVE-2022-32049 | Alta (7.5) | 1.1% | — | 1 jul 2022 | TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the url parameter in the function FUN_00418540. |
| CVE-2022-32048 | Alta (7.5) | 1.1% | — | 1 jul 2022 | TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the command parameter in the function FUN_0041cc88. |
| CVE-2022-32047 | Alta (7.5) | 1.1% | — | 1 jul 2022 | TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00412ef4. |
| CVE-2022-32046 | Alta (7.5) | 1.1% | — | 1 jul 2022 | TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_0041880c. |
| CVE-2022-32045 | Alta (7.5) | 1.1% | — | 1 jul 2022 | TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00413be4. |
| CVE-2022-32044 | Alta (7.5) | 1.1% | — | 1 jul 2022 | TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the password parameter in the function FUN_00413f80. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.