Totolink T6 Firmware vulnerabilities
39 known vulnerabilities affecting totolink/t6_firmware.
Total CVEs
39
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL15HIGH23MEDIUM1
Vulnerabilities
Page 2 of 2
CVE-2022-38827P2CRITICALCVSS 9.8v4.1.5cu.709_b202105182022-09-16
CVE-2022-38827 [CRITICAL] CWE-120 CVE-2022-38827: TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi
TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi
nvd
CVE-2025-8170P2HIGHCVSS 8.8vv4.1.5cu.748_b202110152025-07-25
CVE-2025-8170 [HIGH] CWE-119 CVE-2025-8170: A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748_B20211015. This vulnerab
A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748_B20211015. This vulnerability affects the function tcpcheck_net of the file /router/meshSlaveDlfw of the component MQTT Packet Handler. The manipulation of the argument serverIp leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the
nvd
CVE-2025-7837P2HIGHCVSS 8.8vv4.1.5cu.748_b202110152025-07-19
CVE-2025-7837 [HIGH] CWE-119 CVE-2025-7837: A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected
A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this issue is the function recvSlaveStaInfo of the component MQTT Service. The manipulation of the argument dest leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-7912P2HIGHCVSS 8.8vv4.1.5cu.748_b202110152025-07-20
CVE-2025-7912 [HIGH] CWE-119 CVE-2025-7912: A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B202110
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affects the function recvSlaveUpgstatus of the component MQTT Service. The manipulation of the argument s leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2022-38826P2CRITICALCVSS 9.8v4.1.5cu.709_b202105182022-09-16
CVE-2022-38826 [CRITICAL] CWE-78 CVE-2022-38826: In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.
nvd
CVE-2025-7913P2HIGHCVSS 8.8vv4.1.5cu.748_b202110152025-07-21
CVE-2025-7913 [HIGH] CWE-119 CVE-2025-7913: A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. A
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the function updateWifiInfo of the component MQTT Service. The manipulation of the argument serverIp leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-6916P3HIGHCVSS 8.8vv4.1.5cu.748_b202110152025-06-30
CVE-2025-6916 [HIGH] CWE-287 CVE-2025-6916: A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. T
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of the argument authCode/goURL leads to missing authentication. The attack needs to be initiated within the local network. The exploit has been disclosed to the public an
nvd
CVE-2022-38823P3CRITICALCVSS 9.8v4.1.5cu.709_b202105182022-09-16
CVE-2022-38823 [CRITICAL] CWE-798 CVE-2022-38823: In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.
nvd
CVE-2022-32046P3HIGHCVSS 7.5v4.1.9cu.5179_b202010152022-07-01
CVE-2022-32046 [HIGH] CWE-787 CVE-2022-32046: TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc paramete
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_0041880c.
nvd
CVE-2022-32052P3HIGHCVSS 7.5v4.1.9cu.5179_b202010152022-07-01
CVE-2022-32052 [HIGH] CWE-787 CVE-2022-32052: TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc paramete
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_004137a4.
nvd
CVE-2022-32045P3HIGHCVSS 7.5v4.1.9cu.5179_b202010152022-07-01
CVE-2022-32045 [HIGH] CWE-787 CVE-2022-32045: TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc paramete
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00413be4.
nvd
CVE-2022-32047P3HIGHCVSS 7.5v4.1.9cu.5179_b202010152022-07-01
CVE-2022-32047 [HIGH] CWE-787 CVE-2022-32047: TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc paramete
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00412ef4.
nvd
CVE-2022-32053P3HIGHCVSS 7.5v4.1.9cu.5179_b202010152022-07-01
CVE-2022-32053 [HIGH] CWE-787 CVE-2022-32053: TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac para
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.
nvd
CVE-2022-32048P3HIGHCVSS 7.5v4.1.9cu.5179_b202010152022-07-01
CVE-2022-32048 [HIGH] CWE-787 CVE-2022-32048: TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the command param
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the command parameter in the function FUN_0041cc88.
nvd
CVE-2022-32050P3HIGHCVSS 7.5v4.1.9cu.5179_b202010152022-07-01
CVE-2022-32050 [HIGH] CWE-787 CVE-2022-32050: TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac para
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.
nvd
CVE-2022-32044P3HIGHCVSS 7.5v4.1.9cu.5179_b202010152022-07-01
CVE-2022-32044 [HIGH] CWE-787 CVE-2022-32044: TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the password para
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the password parameter in the function FUN_00413f80.
nvd
CVE-2022-32049P3HIGHCVSS 7.5v4.1.9cu.5179_b202010152022-07-01
CVE-2022-32049 [HIGH] CWE-787 CVE-2022-32049: TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the url parameter
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the url parameter in the function FUN_00418540.
nvd
CVE-2023-7223P3MEDIUMCVSS 6.5v4.1.9cu.5241_b202109232024-01-09
CVE-2023-7223 [MEDIUM] CWE-284 CVE-2023-7223: A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This
A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input showSyslog leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the publi
nvd
CVE-2022-32051P3HIGHCVSS 7.5v4.1.9cu.5179_b202010152022-07-01
CVE-2022-32051 [HIGH] CWE-787 CVE-2022-32051: TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc, week, s
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc, week, sTime, eTime parameters in the function FUN_004133c4.
nvd
← Previous2 / 2