CVE-2026-11620
A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the comp
CVSS
5.3
Medium
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Jun 9, 2026 · Last modified: Jul 23, 2026 · CWE-266 · CWE-272
0.3%EPSS · 30 days0.3%
2026-07-222026-08-19
A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation results in least privilege violation. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
- vuldb.comhttps://vuldb.com/cve/CVE-2026-11620
- vuldb.comhttps://vuldb.com/submit/834825
- vuldb.comhttps://vuldb.com/vuln/369301
- vuldb.comhttps://vuldb.com/vuln/369301/cti
- www.notion.sohttps://www.notion.so/TOTOLink-EX200-V4-0-3c-7646_B20201211-3671f5ba989080ccaa41d9f76fb1906b?source=copy_link
- www.totolink.nethttps://www.totolink.net/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-769996.3 MED—
———A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.4hCVE-2025-622996.6 MED—
———HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.7hCVE-2026-666829.8 CRI—
———Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.3hCVE-2025-156899.8 CRI—
———Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.4hCVE-2026-118619.6 CRI—
——0A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.6hCVE-2026-733909.8 CRI—
——0Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.4h