Vulnerabilities
Summary — last 7 days
New vulnerabilities3,075▲ 488 vs. last week
Critical / high1,457▲ 57 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
1,440 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.31% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/31/2026 | 9/2/2026 | Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter mesh configurations via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (5.4) | 0.31% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter when Wi-Fi is available via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter firewall policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.47% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter dynamic DNS state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.47% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/2/2026 | Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/31/2026 | 9/2/2026 | Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/2/2026 | Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.62% | — | Totolink T6AI | 8/31/2026 | 9/2/2026 | Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.60% | — | Totolink T6AI | 8/31/2026 | 9/2/2026 | Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS) via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/2/2026 | Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/31/2026 | 9/3/2026 | Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/31/2026 | 9/2/2026 | Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |