VendorsTOTOLINKt6_firmwareall versions
Vulnerabilities

TOTOLINK T6 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

39CVEs
CVE-2023-7221
Totolink T6 HTTP POST Request main buffer overflow
Published 2024-01-09 · Modified
10.0EPSS 0.015
CVE-2022-25084
TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
Published 2022-02-22 · Modified
9.8EPSS 0.248
CVE-2022-38828
TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi
Published 2022-09-16 · Modified
9.8EPSS 0.197
CVE-2022-38827
TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi
Published 2022-09-16 · Modified
9.8EPSS 0.122
CVE-2022-25134
A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.030
CVE-2022-25135
A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.029
CVE-2022-25133
A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.029
CVE-2022-25132
A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.029
CVE-2022-25137
A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2022-25136
A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2022-25131
A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2022-25130
A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2022-02-18 · Modified
9.8EPSS 0.022
CVE-2022-38826
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.
Published 2022-09-16 · Modified
9.8EPSS 0.013
CVE-2022-38823
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.
Published 2022-09-16 · Modified
9.8EPSS 0.011
CVE-2025-7862
TOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authentication
Published 2025-07-20 · Analyzed
9.8EPSS 0.011
CVE-2025-8170
TOTOLINK T6 MQTT Packet meshSlaveDlfw tcpcheck_net buffer overflow
Published 2025-07-25 · Analyzed
9.0EPSS 0.011
CVE-2025-7837
TOTOLINK T6 MQTT Service recvSlaveStaInfo buffer overflow
Published 2025-07-19 · Analyzed
9.0EPSS 0.011
CVE-2025-7912
TOTOLINK T6 MQTT Service recvSlaveUpgstatus buffer overflow
Published 2025-07-20 · Analyzed
9.0EPSS 0.011
CVE-2025-7913
TOTOLINK T6 MQTT Service updateWifiInfo buffer overflow
Published 2025-07-20 · Analyzed
9.0EPSS 0.008
CVE-2025-7758
TOTOLINK T6 HTTP POST Request cstecgi.cgi setDiagnosisCfg buffer overflow
Published 2025-07-17 · Analyzed
9.0EPSS 0.008
CVE-2025-7460
TOTOLINK T6 HTTP POST Request cstecgi.cgi setWiFiAclRules buffer overflow
Published 2025-07-11 · Analyzed
9.0EPSS 0.008
CVE-2025-7952
TOTOLINK T6 MQTT Packet wireless.so ckeckKeepAlive command injection
Published 2025-07-22 · Analyzed
8.8EPSS 0.210
CVE-2025-7524
TOTOLINK T6 HTTP POST Request cstecgi.cgi setDiagnosisCfg command injection
Published 2025-07-13 · Modified
8.8EPSS 0.028
CVE-2025-7525
TOTOLINK T6 HTTP POST Request cstecgi.cgi setTracerouteCfg command injection
Published 2025-07-13 · Modified
8.8EPSS 0.028
CVE-2025-7613
TOTOLINK T6 HTTP POST Request cstecgi.cgi CloudSrvVersionCheck command injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.024
CVE-2025-7614
TOTOLINK T6 HTTP POST Request cstecgi.cgi delDevice command injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.024
CVE-2025-7615
TOTOLINK T6 HTTP POST Request cstecgi.cgi clearPairCfg command injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.024
CVE-2025-6916
TOTOLINK T6 formLoginAuth.htm Form_Login missing authentication
Published 2025-06-30 · Analyzed
8.8EPSS 0.009
CVE-2022-32044
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the password parameter in the function FUN_00413f80.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32052
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_004137a4.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32046
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_0041880c.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32051
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc, week, sTime, eTime parameters in the function FUN_004133c4.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32050
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32049
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the url parameter in the function FUN_00418540.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32048
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the command parameter in the function FUN_0041cc88.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32053
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32047
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00412ef4.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2022-32045
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00413be4.
Published 2022-07-01 · Modified
7.5EPSS 0.011
CVE-2023-7223
Totolink T6 cstecgi.cgi access control
Published 2024-01-09 · Modified
6.5EPSS 0.006