Vulnerabilities
Summary — last 7 days
New vulnerabilities3,074▲ 486 vs. last week
Critical / high1,457▲ 57 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
1,440 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN network configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 8/31/2026 | Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 8/31/2026 | Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.62% | — | Totolink T6AI | 8/31/2026 | 8/31/2026 | Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.47% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.50% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.47% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/31/2026 | 9/1/2026 | Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device initialization state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (8.6) | 0.85% | — | Totolink Nr1800xAI | 8/31/2026 | 9/1/2026 | A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Deferred | Low (2.1) | 1.8% | — | Totolink Nr1800xAI | 8/31/2026 | 8/31/2026 | A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Deferred | Low (2.9) | 0.66% | — | Totolink N600rAI | 8/30/2026 | 8/31/2026 | A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such manipulation leads to insufficiently random values. It is possible to launch the attack remotely. This… | |
| Deferred | High (8.5) | 0.83% | 💥 PoC | Totolink A720rAI | 8/30/2026 | 9/1/2026 | A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. The exploit has been publicly… | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain traceroute diagnostic logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.50% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |