Vulnerabilities
Summary — last 7 days
New vulnerabilities3,090▲ 500 vs. last week
Critical / high1,463▲ 62 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
1,440 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi scheduling rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain core wireless settings, including SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain simplified guest Wi-Fi configuration, including guest credentials, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS runtime status via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS configuration, including domain, username, and password, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.50% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.51% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.50% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.50% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.1) | 0.51% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.50% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.50% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.50% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.50% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.33% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, encryption keys, and connected client statistics via sending a crafted… | |
| Deferred | High (7.5) | 0.50% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | High (7.5) | 0.50% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain access-device policy and client state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Medium (4.3) | 0.29% | — | Totolink T6AI | 8/28/2026 | 9/1/2026 | Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Deferred | Critical (9.8) | 0.64% | — | Totolink T6AI | 8/28/2026 | 9/2/2026 | Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message. |