VendorsTOTOLINKt6any version
Vulnerabilities

TOTOLINK T6 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2023-7221
Totolink T6 HTTP POST Request main buffer overflow
Published 2024-01-09 · Modified
10.0EPSS 0.015
CVE-2022-25084
TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
Published 2022-02-22 · Modified
9.8EPSS 0.248
CVE-2022-25134
A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.030
CVE-2022-25135
A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.029
CVE-2022-25132
A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.029
CVE-2022-25133
A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.029
CVE-2022-25130
A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2022-25131
A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2022-25136
A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2022-25137
A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2025-7615
TOTOLINK T6 HTTP POST Request cstecgi.cgi clearPairCfg command injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.024
CVE-2025-7614
TOTOLINK T6 HTTP POST Request cstecgi.cgi delDevice command injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.024
CVE-2025-7613
TOTOLINK T6 HTTP POST Request cstecgi.cgi CloudSrvVersionCheck command injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.024
CVE-2025-6916
TOTOLINK T6 formLoginAuth.htm Form_Login missing authentication
Published 2025-06-30 · Analyzed
8.8EPSS 0.009
CVE-2022-32044
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the password parameter in the function FUN_00413f80.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32048
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the command parameter in the function FUN_0041cc88.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32049
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the url parameter in the function FUN_00418540.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32050
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32051
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc, week, sTime, eTime parameters in the function FUN_004133c4.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32052
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_004137a4.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32053
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32047
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00412ef4.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32046
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_0041880c.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32045
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00413be4.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2023-7223
Totolink T6 cstecgi.cgi access control
Published 2024-01-09 · Modified
6.5EPSS 0.006