« Volver al listado

Totolink

Totolink T6: vulnerabilidades y CVE

Totolink T6 tiene 151 vulnerabilidades publicadas, 151 de ellas en los últimos 12 meses. 78 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE151
Últimos 12 meses151
Críticas78
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-51770Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT…
CVE-2026-51769Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted MQTT message to the…
CVE-2026-51768Alta (7.5)0.47%—1 sept 2026
Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the master device via sending a crafted MQTT message to…
CVE-2026-51767Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the…
CVE-2026-51766Alta (7.5)0.60%—1 sept 2026
Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending…
CVE-2026-51765Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the…
CVE-2026-51764Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the…
CVE-2026-51763Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker…
CVE-2026-51762Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via…
CVE-2026-51761Media (5.3)0.40%—1 sept 2026
Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.
CVE-2026-51760Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT…
CVE-2026-51757Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted…
CVE-2026-51756Media (5.9)0.43%—1 sept 2026
Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to…
CVE-2026-51754Crítica (9.8)0.62%—1 sept 2026
Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT message to the…
CVE-2026-51752Media (5.3)0.41%—1 sept 2026
Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT…
CVE-2026-51751Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via…
CVE-2026-51750Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the…
CVE-2026-51748Media (5.9)0.43%—1 sept 2026
Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the…
CVE-2026-51747Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a crafted MQTT message…
CVE-2026-51745Media (5.3)0.40%—1 sept 2026
Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message to the cs_broker…
CVE-2026-51744Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending…
CVE-2026-51743Crítica (9.1)0.51%—1 sept 2026
Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker…
CVE-2026-51742Media (5.9)0.43%—1 sept 2026
Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51741Crítica (9.8)0.64%—1 sept 2026
Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51740Crítica (9.8)0.64%—31 ago 2026
Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51739Media (5.9)0.43%—31 ago 2026
Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to…
CVE-2026-51738Crítica (9.8)0.64%—31 ago 2026
Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request…
CVE-2026-51737Media (5.3)0.40%—31 ago 2026
Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51736Crítica (9.1)0.51%—31 ago 2026
Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51735Alta (7.5)0.50%—31 ago 2026
Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application109
  2. T1565.001 Stored Data Manipulation22
  3. T1005 Data from Local System19
  4. T1565.002 Transmitted Data Manipulation11
  5. T1552.001 Credentials In Files6
  6. T1552.007 Container API6

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Totolink