TOTOLINK T6 版本 4.1.5cu.748_B20211015 中, 函数存在访问控制不当的问题。未认证的攻击者可以通过向 发送特制的 POST 请求,获取云端固件下载状态信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82608 | 7.4 HIGH | Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds |
| CVE-2026-82630 | 7.3 HIGH | PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection |
| CVE-2026-82600 | 7.3 HIGH | SeaCMS zyapi.php sql injection |
| CVE-2026-82598 | 7.3 HIGH | SeaCMS Template search.php parseIf code injection |
| CVE-2026-82603 | 5.4 MEDIUM | SeaCMS Comment Cache member.php del_pl path traversal |
| CVE-2026-82599 | 5.4 MEDIUM | SeaCMS Avatar Upload member.php unlink path traversal |
| CVE-2026-82623 | 5.3 MEDIUM | open62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange |
| CVE-2026-82602 | 5.3 MEDIUM | SeaCMS ass.php authorization |
| CVE-2026-82601 | 4.3 MEDIUM | SeaCMS err.php cross site scripting |
| CVE-2026-82805 | 4.3 MEDIUM | Typora Mermaid Rendering cross site scripting |
| CVE-2026-82596 | 3.3 LOW | LatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause memory corru |
| CVE-2026-51706 | TOTOLINK T6 4.1.5 认证缺失致QoS配置越权 | |
| CVE-2026-51698 | TOTOLINK T6 4.1.5 越权控制漏洞 | |
| CVE-2026-51708 | T6 4.1.5 版本 TOTOLINK T6 未认证访问控制漏洞 | |
| CVE-2026-51710 | TOTOLINK T6 4.1.5 认证缺失漏洞 | |
| CVE-2026-51703 | TOTOLINK T6 4.1.5 认证绕过及越权漏洞 | |
| CVE-2026-51152 | QD多个版本/har/test接口未认证SSRF漏洞 | |
| CVE-2026-51704 | TOTOLINK T6 4.1.5 未授权访问控制漏洞 | |
| CVE-2026-51700 | TOTOLINK T6 4.1.5 访问控制不当漏洞 | |
| CVE-2026-51701 | TOTOLINK T6 4.1.5 未授权访问控制漏洞 |
Showing top 20 of 69 CVEs. View all on vendor page → →
No comments yet