vciy

Incorrect access control: 148 records in one advisory

148 records announced together, published between 2026-08-28 and 2026-09-01, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

Every record names something of its own, listed against it below.

What this page does not cover

This batch is 148 of the 151 records that cite the same advisory. The other 3 are different findings announced alongside it.

None of those 3 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2026-51610rebootsystem immediate
CVE-2026-51611startslavereboot
CVE-2026-51613getdeviceinfo identification details
CVE-2026-51614getaccessdevicecfg
CVE-2026-51616getwaniecfg
CVE-2026-51617getsysstatuscfg operation version serial
CVE-2026-51618getwizardcfg setup wizard onboarding
CVE-2026-51619getonlineclient online
CVE-2026-51620getnetinfocfg topology interface
CVE-2026-51621getinitcfg
CVE-2026-51623getddnsstatus public
CVE-2026-51624getstationmacbyip
CVE-2026-51625getwifieasycfg
CVE-2026-51626getwifiwpscfg
CVE-2026-51627getiptvcfg igmp
CVE-2026-51628getgeneratewifiwpspin generate new
CVE-2026-51630getddnscfg domain password
CVE-2026-51632getwifiadvancedcfg advanced
CVE-2026-51633getwifieasyguestcfg simplified credentials
CVE-2026-51634getwifibasiccfg core
CVE-2026-51635getwifischedulecfg
CVE-2026-51636getwifiaclrules
CVE-2026-51637getmeshportaltable portal table
CVE-2026-51638getwifiguestcfg
CVE-2026-51639getapwifischcfg ap-specific
CVE-2026-51640getmeshneighbortable
CVE-2026-51641getwifimeshconfig
CVE-2026-51642getmeshroutingtable routing
CVE-2026-51643getntpcfg ntp
CVE-2026-51644getcrpcconfig
CVE-2026-51645getpasswordcfg
CVE-2026-51646getparentalrules
CVE-2026-51647getcrpccfg
CVE-2026-51648getwaninfo returned by
CVE-2026-51649getdiagnosiscfg log contents
CVE-2026-51650getremotecfg remote-management
CVE-2026-51651getsmartqoscfg
CVE-2026-51652getupnpcfg parsed port-mapping
CVE-2026-51653getstoragecfg storage feature
CVE-2026-51654getschedulecfg scheduled-reboot
CVE-2026-51655getmacfilterrules
CVE-2026-51656getvpnpasscfg vpn pass-through
CVE-2026-51657getsyslogcfg syslog-related
CVE-2026-51659geturlfilterrules
CVE-2026-51660getipportfilterrules
CVE-2026-51661getportforwardrules
CVE-2026-51662getcloudsrvcheckstatus
CVE-2026-51663getwifiapcliscan scans ap-client scan
CVE-2026-51664gettelnetcfg telnet
CVE-2026-51665gettraceroutecfg
CVE-2026-51666setwizardcfg initialization
CVE-2026-51667getwifiipmactable mac-to-ip mappings
CVE-2026-51668setlanguagecfg language
CVE-2026-51669getpaircfg mesh-slave
CVE-2026-51670getslaveupdate query affect bookkeeping
CVE-2026-51671getclouddownloadstatus
CVE-2026-51672getroamingcfg flag
CVE-2026-51674setschedulecfg configure forced tasks
CVE-2026-51675setwaniecfg uplink
CVE-2026-51676setaccessdevicecfg
CVE-2026-51677setupnpcfg
CVE-2026-51678setsyslogcfg logging
CVE-2026-51679setpasswordcfg administrator account
CVE-2026-51680setledcfg led
CVE-2026-51681setremotecfg wan-side administration
CVE-2026-51684setstoragecfg storage-related
CVE-2026-51686setwifieasycfg networks
CVE-2026-51687setwifieasyguestcf create
CVE-2026-51688setwifisignalcfg reduce power cause
CVE-2026-51689setupgradefw firmware-upgrade changes
CVE-2026-51690setwancfg provisioning connectivity
CVE-2026-51691setuploadsetting
CVE-2026-51692setwifiguestcfg establish
CVE-2026-51693setvpnpasscfg edge
CVE-2026-51694setstaticdhcprules add
CVE-2026-51695setddnscfg dynamic dns
CVE-2026-51696setportforwardrules
CVE-2026-51697setiptvcfg
CVE-2026-51698seturlfilterrules browsing
CVE-2026-51700setwifiadvancedcfg
CVE-2026-51701setmacfilterrules
CVE-2026-51702setipportfilterrules
CVE-2026-51703setwifischedulecfg when is available
CVE-2026-51704setwifimeshconfig configurations
CVE-2026-51705setwifimeshname rename
CVE-2026-51706setsmartqoscfg traffic handling
CVE-2026-51708setwifiwpscfg
CVE-2026-51709setwifibasiccfg
CVE-2026-51710setparentalrules
CVE-2026-51711setwifiwpsstart open window
CVE-2026-51712setapwifischcfg windows
CVE-2026-51713setmanualdialcfg dial
CVE-2026-51714setroamingcfg
CVE-2026-51715delmacfilterrules
CVE-2026-51716delportforwardrules delete
CVE-2026-51717setopmodecfg operating
CVE-2026-51718delstaticdhcprules reservations
CVE-2026-51719delurlfilterrules
CVE-2026-51720delipportfilterrules
CVE-2026-51721setpaircfg
CVE-2026-51722setwifirepeatercfg repoint
CVE-2026-51723uploadcustommodule install custom cgi
CVE-2026-51724delsmartqoscfg
CVE-2026-51725ntpsyncwithhost clock
CVE-2026-51726delparentalrules
CVE-2026-51727systemsettings import export
CVE-2026-51728uploadfirmwarefile image
CVE-2026-51729deldevice deletion managed
CVE-2026-51730delwifiaclrules
CVE-2026-51731delvlancfg vlan
CVE-2026-51732delwifischedulecfg
CVE-2026-51734informslaveupdate coordination
CVE-2026-51735showsyslog recent
CVE-2026-51736clearsyslog
CVE-2026-51737cleartraceroutelog
CVE-2026-51738loaddefsettings
CVE-2026-51739cloudsrvversioncheck checks
CVE-2026-51740killprocess terminate critical
CVE-2026-51741cleardiagnosislog diagnosis
CVE-2026-51742discoverwan discovery logic
CVE-2026-51743guest_wifi_sync virtual ap interfaces
CVE-2026-51744recv_mesh_info_sync
CVE-2026-51745updatepristalist station list
CVE-2026-51747keepalive emit indirect heartbeat
CVE-2026-51748sendstaticinfotomaster stored
CVE-2026-51750updateprichannel rescan switch channel
CVE-2026-51751delslavedevice specified management
CVE-2026-51752staticinfosend reporting configured
CVE-2026-51754updateslaveiplist
CVE-2026-51756meshslaveupgfw flashing using existing
CVE-2026-51757meshslaveupdate
CVE-2026-51760informsyncupgfw mass-trigger activity across
CVE-2026-51761updatelanip
CVE-2026-51762meshinfokick kick clean stale
CVE-2026-51763freestaclient forcibly disconnect clients
CVE-2026-51764recvslavecloudcheckstatus cloud-result tracking
CVE-2026-51765recvindirectmeshinfo insert replace
CVE-2026-51766setdevreboot fan out commands
CVE-2026-51767recvclearpaircfg
CVE-2026-51768setelinkqosconfig privileged
CVE-2026-51769remotecloudupdatecheck restart
CVE-2026-51770sendtomasterqosconfig forward

148 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.