A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748B20211015. This vulnerability affects the function tcpchecknet of the file /router/meshSlaveDlfw of the component MQTT Packet Handler. The manipulation of the argument serverIp leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748B20211015. Affected is the function updateWifiInfo of the component MQTT Service. The manipulation of the argument serverIp leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748B20211015. This issue affects the function recvSlaveUpgstatus of the component MQTT Service. The manipulation of the argument s leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
A vulnerability was found in TOTOLINK T6 4.1.5cu.748B20211015 and classified as critical. Affected by this issue is the function recvSlaveStaInfo of the component MQTT Service. The manipulation of the argument dest leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748B20211015. Affected by this issue is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ip leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
A vulnerability has been found in TOTOLINK T6 4.1.5cu.748B20211015 and classified as critical. Affected by this vulnerability is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748B20211015. This affects the function FormLogin of the file /formLoginAuth.htm. The manipulation of the argument authCode/goURL leads to missing authentication. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used.
TOTOLINK T6 V4.1.9cu.5179B20201015 was discovered to contain a stack overflow via the password parameter in the function FUN00413f80.
TOTOLINK T6 V4.1.9cu.5179B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN00413be4.
TOTOLINK T6 V4.1.9cu.5179B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN00412ef4.
TOTOLINK T6 V4.1.9cu.5179B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN0041880c.
TOTOLINK T6 V4.1.9cu.5179B20201015 was discovered to contain a stack overflow via the command parameter in the function FUN0041cc88.
TOTOLINK T6 V4.1.9cu.5179B20201015 was discovered to contain a stack overflow via the url parameter in the function FUN00418540.
TOTOLINK T6 V4.1.9cu.5179B20201015 was discovered to contain a stack overflow via the desc, week, sTime, eTime parameters in the function FUN004133c4.
TOTOLINK T6 V4.1.9cu.5179B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN0041af40.
TOTOLINK T6 V4.1.9cu.5179B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN004137a4.
TOTOLINK T6 V4.1.9cu.5179B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN0041621c.