T6
17 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for T6, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
T6 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 13 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High8
- Medium7
Latest CVEs
The 15 most recently published vulnerabilities affecting T6.
- CVE-2025-8170TOTOLINK T6 MQTT Packet meshSlaveDlfw tcpcheck_net buffer overflow8.8
- CVE-2025-7952TOTOLINK T6 MQTT Packet wireless.so ckeckKeepAlive command injection6.3
- CVE-2025-7913TOTOLINK T6 MQTT Service updateWifiInfo buffer overflow8.8
- CVE-2025-7912TOTOLINK T6 MQTT Service recvSlaveUpgstatus buffer overflow8.8
- CVE-2025-7862TOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authentication7.3
- CVE-2025-7837TOTOLINK T6 MQTT Service recvSlaveStaInfo buffer overflow8.8
- CVE-2025-7758TOTOLINK T6 HTTP POST Request cstecgi.cgi setDiagnosisCfg buffer overflow8.8
- CVE-2025-7615TOTOLINK T6 HTTP POST Request cstecgi.cgi clearPairCfg command injection6.3
- CVE-2025-7614TOTOLINK T6 HTTP POST Request cstecgi.cgi delDevice command injection6.3
- CVE-2025-7613TOTOLINK T6 HTTP POST Request cstecgi.cgi CloudSrvVersionCheck command injection6.3
- CVE-2025-7525TOTOLINK T6 HTTP POST Request cstecgi.cgi setTracerouteCfg command injection6.3
- CVE-2025-7524TOTOLINK T6 HTTP POST Request cstecgi.cgi setDiagnosisCfg command injection6.3
- CVE-2025-7460TOTOLINK T6 HTTP POST Request cstecgi.cgi setWiFiAclRules buffer overflow8.8
- CVE-2025-6916TOTOLINK T6 formLoginAuth.htm Form_Login missing authentication8.8
- CVE-2023-7223Totolink T6 cstecgi.cgi access control5.3
Product grouping is registry-driven, with AI assist and human review. How it works