Totolink
Totolink T6: vulnerabilidades y CVE
Totolink T6 tiene 151 vulnerabilidades publicadas, 151 de ellas en los últimos 12 meses. 78 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE151
Últimos 12 meses151
Críticas78
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-51770 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT… |
| CVE-2026-51769 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted MQTT message to the… |
| CVE-2026-51768 | Alta (7.5) | 0.47% | — | 1 sept 2026 | Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the master device via sending a crafted MQTT message to… |
| CVE-2026-51767 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the… |
| CVE-2026-51766 | Alta (7.5) | 0.60% | — | 1 sept 2026 | Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending… |
| CVE-2026-51765 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the… |
| CVE-2026-51764 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the… |
| CVE-2026-51763 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker… |
| CVE-2026-51762 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via… |
| CVE-2026-51761 | Media (5.3) | 0.40% | — | 1 sept 2026 | Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component. |
| CVE-2026-51760 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT… |
| CVE-2026-51757 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted… |
| CVE-2026-51756 | Media (5.9) | 0.43% | — | 1 sept 2026 | Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to… |
| CVE-2026-51754 | Crítica (9.8) | 0.62% | — | 1 sept 2026 | Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT message to the… |
| CVE-2026-51752 | Media (5.3) | 0.41% | — | 1 sept 2026 | Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT… |
| CVE-2026-51751 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via… |
| CVE-2026-51750 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the… |
| CVE-2026-51748 | Media (5.9) | 0.43% | — | 1 sept 2026 | Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the… |
| CVE-2026-51747 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a crafted MQTT message… |
| CVE-2026-51745 | Media (5.3) | 0.40% | — | 1 sept 2026 | Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message to the cs_broker… |
| CVE-2026-51744 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending… |
| CVE-2026-51743 | Crítica (9.1) | 0.51% | — | 1 sept 2026 | Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker… |
| CVE-2026-51742 | Media (5.9) | 0.43% | — | 1 sept 2026 | Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |
| CVE-2026-51741 | Crítica (9.8) | 0.64% | — | 1 sept 2026 | Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |
| CVE-2026-51740 | Crítica (9.8) | 0.64% | — | 31 ago 2026 | Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |
| CVE-2026-51739 | Media (5.9) | 0.43% | — | 31 ago 2026 | Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to… |
| CVE-2026-51738 | Crítica (9.8) | 0.64% | — | 31 ago 2026 | Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request… |
| CVE-2026-51737 | Media (5.3) | 0.40% | — | 31 ago 2026 | Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |
| CVE-2026-51736 | Crítica (9.1) | 0.51% | — | 31 ago 2026 | Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |
| CVE-2026-51735 | Alta (7.5) | 0.50% | — | 31 ago 2026 | Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.