CVE-2026-51736
Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system l
CVSS
9.1
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 31, 2026 · Last modified: Sep 1, 2026 · CWE-284
Not enough EPSS history yet.
Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- github.comhttps://github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
- github.comhttps://github.com/ShengWu00/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
- www.totolink.nethttps://www.totolink.net/
- www.totolink.nethttps://www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-737414.3 MED—
———A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation could allow an attacker to access limited data beyond what is authorized by the user's existing privilege level.10hCVE-2024-7953——
———A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could create, modify, and delete their own project.10hCVE-2026-517667.5 HIG—
———Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component.10hCVE-2026-517615.3 MED—
———Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.10hCVE-2026-517565.9 MED—
———Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.10hCVE-2026-517525.3 MED—
———Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component.10h