📦 T6 Firmware

by Totolink

🔍 What is T6 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-7221

CRITICAL CVSS 9.8 Jan 9, 2024

This critical buffer overflow vulnerability in Totolink T6 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the login endpoint. Attackers ca...

CVE-2022-25084

CRITICAL CVSS 9.8 Feb 24, 2022

This critical vulnerability in TOTOLink T6 routers allows remote attackers to execute arbitrary operating system commands via the QUERY_STRING parameter. Attackers can gain complete control of affecte...

CVE-2022-25130

CRITICAL CVSS 9.8 Feb 19, 2022

This CVE describes a command injection vulnerability in TOTOLINK router firmware that allows attackers to execute arbitrary commands via crafted MQTT packets. Attackers can gain full control of affect...

CVE-2022-25132

CRITICAL CVSS 9.8 Feb 19, 2022

This is a critical command injection vulnerability in TOTOLINK T6 routers that allows attackers to execute arbitrary commands on affected devices by sending specially crafted MQTT packets. Attackers c...

CVE-2022-25134

CRITICAL CVSS 9.8 Feb 19, 2022

This is a critical command injection vulnerability in TOTOLINK T6 router firmware that allows attackers to execute arbitrary commands via crafted MQTT packets. Attackers can gain complete control of a...

CVE-2022-25136

CRITICAL CVSS 9.8 Feb 19, 2022

This CVE describes a command injection vulnerability in TOTOLINK router firmware that allows attackers to execute arbitrary commands via crafted MQTT packets. Attackers can gain full control of affect...

CVE-2025-7913

HIGH CVSS 8.8 Jul 21, 2025

This critical vulnerability in TOTOLINK T6 routers allows remote attackers to execute arbitrary code via a buffer overflow in the MQTT service's updateWifiInfo function. Attackers can exploit this by ...

CVE-2025-7862

HIGH CVSS 7.3 Jul 20, 2025

This critical vulnerability in TOTOLINK T6 routers allows remote attackers to enable Telnet service without authentication by manipulating the telnet_enabled parameter. Affected systems are TOTOLINK T...

CVE-2025-7837

HIGH CVSS 8.8 Jul 19, 2025

A critical buffer overflow vulnerability exists in the MQTT service of TOTOLINK T6 routers, specifically in the recvSlaveStaInfo function. Attackers can remotely exploit this by manipulating the 'dest...

CVE-2025-7460

HIGH CVSS 8.8 Jul 11, 2025

This critical vulnerability in TOTOLINK T6 routers allows remote attackers to execute arbitrary code via a buffer overflow in the WiFi ACL rules configuration function. Attackers can exploit this by s...

CVE-2025-6916

HIGH CVSS 8.8 Jun 30, 2025

This critical vulnerability in TOTOLINK T6 routers allows attackers to bypass authentication on the login form by manipulating authCode/goURL parameters. Attackers within the local network can gain un...

CVE-2025-7952

MEDIUM CVSS 6.3 Jul 22, 2025

This critical vulnerability in TOTOLINK T6 routers allows remote attackers to execute arbitrary commands via command injection in the MQTT packet handler. Attackers can exploit this to gain unauthoriz...

CVE-2025-7614

MEDIUM CVSS 6.3 Jul 14, 2025

This critical vulnerability in TOTOLINK T6 routers allows remote attackers to execute arbitrary commands via command injection in the delDevice function. Attackers can exploit this by sending speciall...

CVE-2025-7524

MEDIUM CVSS 6.3 Jul 13, 2025

This critical vulnerability in TOTOLINK T6 routers allows remote attackers to execute arbitrary commands via command injection in the HTTP POST request handler. Attackers can exploit this by manipulat...