Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

IONIX THREAT CENTER

A free, curated feed of CVEs that can be remotely exploited by an unauthenticated attacker, verified and published the moment they emerge. No noise, no triage backlog. Just the exploitable vulnerabilities that actually demand your attention, delivered in real time.

Be the first to know when new zero-days emerge:

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51731 – Unauthenticated VLAN Configuration Tampering – TOTOLINK T6 (firmware 4.1.5cu.748_B2

CVE-2026-51731 is an improper access control vulnerability (CWE-284) in the delVlanCfg function of the TOTOLINK T6 router's web management CGI interface, running firmware version 4.1.5cu.748_B20211015. The flaw allows an unauthenticated, remote attacker to delete VLAN configuration entries by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The vulnerability carries a CRITICAL CVSS v3.1 base score of 9.1.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-66357 – HTTP Request Smuggling – Erlang/OTP inets httpd (versions 17.0–29.0.5)

CVE-2026-66357 is an HTTP request smuggling vulnerability (CWE-444: Inconsistent Interpretation of HTTP Requests) affecting the httpd server component of the inets application bundled with Erlang/OTP. The root cause is that httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines): every CRLF sequence followed by a non-CRLF octet is unconditionally treated as the start of a new header rather than as a continuation of the previous one. The issue carries a CVSS score of 8.3 (High) and is remotely exploitable without authentication.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-70399 – Unauthenticated Denial of Service – Erlang/OTP inets httpd Module

CVE-2026-70399 is a resource-exhaustion (CWE-770: Allocation of Resources Without Limits or Throttling) vulnerability in the inets httpd HTTP server component of Erlang/OTP. Due to a coding defect in the connection-acceptance logic, servers that do not explicitly configure the max_clients option silently accept an unlimited number of simultaneous connections instead of enforcing the documented default limit of 150. An unauthenticated remote attacker can exploit this by opening a large number of connections, causing denial of service through exhaustion of server processes, memory, and file descriptors.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-73812 – HTTP Request Smuggling – Erlang/OTP inets httpd

CVE-2026-73812 is an HTTP request smuggling vulnerability (CWE-444: Inconsistent Interpretation of HTTP Requests) in the inets httpd HTTP server module of Erlang/OTP. The httpd server accepts requests that simultaneously contain both Transfer-Encoding: chunked and Content-Length headers without rejecting them or closing the connection, in violation of RFC 9112 §6.1. When httpd sits behind a reverse proxy that determines message boundaries differently (e.g., by prioritizing Content-Length), this framing disagreement can be abused for a CL.TE-style desync attack.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-71380 – Denial of Service (Slowloris-style Worker Exhaustion) – Erlang/OTP inets httpd Serv

CVE-2026-71380 is a Missing Release of Resource after Effective Lifetime (CWE-772) vulnerability in the httpd component of Erlang/OTP's inets HTTP server. It allows an unauthenticated, remote attacker to cause a denial of service by sending a well-formed HTTP request with a large Content-Length header and then stalling before delivering the full request body, permanently parking a server worker. The issue carries a CVSS score of 8.7 (High) and affects a wide range of OTP releases.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51721 – Unauthenticated Access Control Bypass – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51721 is an incorrect access control vulnerability in the setPairCfg function of the TOTOLINK T6 web management interface, firmware version 4.1.5cu.748_B20211015. It allows an unauthenticated remote attacker to alter the device's mesh pairing state, and has been assigned a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51726 – Improper Access Control (Unauthenticated Parental-Rule Removal) – TOTOLINK T6 4.1.5

CVE-2026-51726 is an improper access control vulnerability (CWE-284) in the delParentalRules function of the TOTOLINK T6 router web management interface, firmware version 4.1.5cu.748_B20211015. The flaw allows an unauthenticated, remote attacker to remove parental-control rules by sending a crafted POST request to the device's CGI handler. It carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51715 – Unauthenticated MAC Filter Rule Deletion – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51715 is an incorrect access control vulnerability in the delMacFilterRules function of the TOTOLINK T6 router's web management interface (firmware 4.1.5cu.748_B20211015). It allows a remote, unauthenticated attacker to remove configured MAC filter rules by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51729 – Unauthenticated Device Deletion / Access Control Bypass – TOTOLINK T6 4.1.5cu.748_B

CVE-2026-51729 is an incorrect access control vulnerability in the delDevice function of the TOTOLINK T6 router firmware (version 4.1.5cu.748_B20211015). The flaw allows an unauthenticated, remote attacker to send a crafted HTTP POST request to the device's CGI web management interface and delete a managed "slave" device entry without any authentication. It carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51699 – Unauthenticated Internal Host Exposure via DMZ Config – TOTOLINK T6 4.1.5cu.748_B20

CVE-2026-51699 is an incorrect access control (CWE-284) vulnerability in the setDmzCfg function of the TOTOLINK T6 web management interface, firmware version 4.1.5cu.748_B20211015. The CGI endpoint fails to enforce authentication on DMZ configuration requests, allowing an unauthenticated remote attacker to expose an internal host to the internet. The flaw carries a critical CVSS v3.1 score of 9.8.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51724 – Unauthenticated Improper Access Control – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51724 is an improper access control vulnerability (CWE-284) affecting the delSmartQosCfg function on TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. The flaw allows an unauthenticated remote attacker to remove configured Smart QoS rules by sending a crafted POST request to the device's CGI interface. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51696 – Unauthenticated Port-Forward Rule Exposure – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51696 is an incorrect access control vulnerability (CWE-284) in the setPortForwardRules function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. The flaw allows an unauthenticated remote attacker to send a crafted HTTP POST request to the device's management CGI endpoint and modify port-forwarding rules, exposing internal services to the internet. The issue carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51700 – Unauthenticated Wi-Fi Configuration Tampering (Improper Access Control) – TOTOLINK

CVE-2026-51700 is an improper access control vulnerability (CWE-284) in the setWiFiAdvancedCfg function of the TOTOLINK T6 router's web management interface, firmware version 4.1.5cu.748_B20211015. The function fails to verify that the requester is authenticated before processing wireless configuration changes, allowing a remote, unauthenticated attacker to submit a crafted request that degrades wireless behavior. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51734 – Unauthenticated Access Control Bypass – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51734 is an incorrect access control vulnerability (CWE-284) in the informSlaveUpdate function of the TOTOLINK T6 router, firmware version 4.1.5cu.748_B20211015. The flaw allows an unauthenticated remote attacker to trigger mesh slave update coordination logic on the device by sending a crafted POST request to the device's web management CGI endpoint. The issue is rated CRITICAL with a CVSS v3.1 base score of 9.8.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51693 – Unauthenticated Access Control Bypass – TOTOLINK T6 Router Firmware 4.1.5cu.748_B20

CVE-2026-51693 is a critical incorrect access control vulnerability (CVSS 9.8) in the setVpnPassCfg function of the TOTOLINK T6 router's web management interface, firmware version 4.1.5cu.748_B20211015. The endpoint fails to enforce authentication, allowing a remote, unauthenticated attacker to send a crafted POST request that weakens the device's edge filtering (firewall/VPN passthrough) configuration. This CVE is one of a large batch of similarly structured incorrect-access-control flaws disclosed in the same firmware build, all reachable through the device's /cgi-bin/cstecgi.cgi CGI handler.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51698 – Unauthenticated Access Control Bypass (URL Filter Policy Tampering) – TOTOLINK T6 4

CVE-2026-51698 is an incorrect access control vulnerability in the setUrlFilterRules function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. The flaw allows an unauthenticated, remote attacker to modify device browsing/URL filtering policies by sending a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint. It carries a CRITICAL CVSS v3.1 base score of 9.1.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51697 – Unauthenticated IPTV Configuration Tampering – TOTOLINK T6 Firmware 4.1.5cu.748_B20

CVE-2026-51697 is an incorrect access control vulnerability (CWE-284) in the setIptvCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. It allows an unauthenticated remote attacker to alter the device's IPTV service configuration by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51740 – Unauthenticated Denial of Service (killProcess) – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51740 is an incorrect access control vulnerability in the killProcess function of the TOTOLINK T6 web management interface, firmware version 4.1.5cu.748_B20211015. The flaw allows an unauthenticated remote attacker to send a crafted POST request that terminates critical device processes, resulting in denial of service. The issue carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51152 – Unauthenticated SSRF – QD 20220208 through 20250803

CVE-2026-51152 is a Server-Side Request Forgery (SSRF) vulnerability affecting QD (QD-Today), a Chinese-language HTTP request scheduling framework built on HAR Editor and Tornado Server. The unauthenticated /har/test endpoint allows attackers to force the QD server to issue arbitrary outbound HTTP requests to internal network resources and cloud metadata services. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51701 – Unauthenticated Access Control Bypass – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51701 is an incorrect access control vulnerability (CWE-284) in the setMacFilterRules function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. The flaw allows an unauthenticated, remote attacker to modify the device's MAC address filtering/access control rules by sending a crafted POST request to the router's CGI endpoint. The issue is rated critical with a CVSS v3.1 base score of 9.1.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51717 – Unauthenticated Operating Mode Change – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51717 is an incorrect access control vulnerability in the setOpModeCfg function of the TOTOLINK T6 router, firmware version 4.1.5cu.748_B20211015. The flaw allows an unauthenticated remote attacker to send a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint and change the router's operating mode without providing any credentials. It carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51718 – Unauthenticated Configuration Tampering (DHCP Rule Deletion) – TOTOLINK T6 4.1.5cu.

CVE-2026-51718 is an incorrect access control vulnerability in the delStaticDhcpRules function of the TOTOLINK T6 router, firmware version 4.1.5cu.748_B20211015. The flaw allows an unauthenticated, remote attacker to delete static DHCP reservations by sending a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-18210 – SQL Injection – TRtek Products’s Store prior to v030631b2

CVE-2026-18210 is a critical SQL injection vulnerability affecting TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company's "Products's Store" application. The flaw stems from improper neutralization of special elements used in SQL commands (CWE-89), allowing an unauthenticated, remote attacker to manipulate backend SQL queries. With a CVSS v3.1 base score of 9.8 (Critical), successful exploitation can fully compromise the confidentiality, integrity, and availability of the affected system.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51711 – Unauthenticated WPS Pairing Activation (Access Control Bypass) – TOTOLINK T6 4.1.5c

CVE-2026-51711 is an incorrect access control vulnerability (CWE-284) in the setWiFiWpsStart function of the TOTOLINK T6 router web management interface, firmware version 4.1.5cu.748_B20211015. The flaw allows an unauthenticated remote attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and open a Wi-Fi Protected Setup (WPS) pairing window without any credentials. The issue carries a CVSS v3.1 base score of 9.1 (Critical) and requires no user interaction to exploit.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-19513 – Unauthenticated Arbitrary File Upload (RCE) – Gravity Forms ≤ 3.0.2

CVE-2026-19513 is an unauthenticated arbitrary file upload vulnerability in the Gravity Forms plugin for WordPress, affecting all versions up to and including 3.0.2. The flaw resides in the GFAsyncUpload::upload() function and, on servers that do not restrict script execution in the uploads directory, can lead to remote code execution; on other configurations it can result in stored cross-site scripting. The issue carries a CVSS v3.1 base score of 8.1 (High).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-18808 – Unauthenticated Remote Code Execution (Code Injection) – Klemsan KIO before v1.9

CVE-2026-18808 is a critical Improper Control of Generation of Code ("Code Injection", CWE-94) vulnerability affecting Klemsan Electrical Electronics Inc.'s KIO (Klemsan Internet Objects) IoT platform. The flaw allows an unauthenticated remote attacker to inject and execute arbitrary code on the affected system, resulting in unauthenticated Remote Code Execution (RCE). It carries a CVSS v3.1 base score of 9.8 (Critical), reflecting network-exploitability with no authentication or user interaction required.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-84218 – JNDI Injection via JSR-160 Proxy Denylist Bypass – Jolokia jolokia-core 1.5.0–1.x a

CVE-2026-84218 is a JNDI injection vulnerability in the Jolokia agent's JSR-160 proxy mode, caused by an incomplete denylist that was meant to close out the original proxy JNDI flaw, CVE-2018-1000130. Because the denylist regex only matches a narrow set of service:jmx:rmi:///jndi/ldap: strings, attackers can submit alternate JMX service URL forms (such as ldaps:// schemes or URLs with a non-empty JMX host component) to bypass the filter and force the Jolokia agent to perform a JNDI lookup against an attacker-controlled LDAP server. The issue affects Jolokia's jolokia-core component and carries a…

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51709 – Unauthenticated Wi-Fi Configuration Tampering – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51709 is a critical improper access control vulnerability (CWE-284) in the setWiFiBasicCfg function of the TOTOLINK T6 router firmware. The flaw allows an unauthenticated, remote attacker to reconfigure the device's primary Wi-Fi settings by sending a crafted POST request, with no credentials or user interaction required. The issue carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51710 – Unauthenticated Access Control Bypass – TOTOLINK T6 firmware 4.1.5cu.748_B20211015

CVE-2026-51710 is an improper access control vulnerability in the setParentalRules function of the TOTOLINK T6 router, firmware version 4.1.5cu.748_B20211015. The flaw allows an unauthenticated, remote attacker to alter the device's parental-control configuration by sending a crafted POST request to the router's CGI management interface. The issue carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51676 – Unauthenticated Access-Device Policy Tampering – TOTOLINK T6 Firmware 4.1.5cu.748_B

CVE-2026-51676 is an incorrect access control vulnerability in the setAccessDeviceCfg function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. The flaw allows an unauthenticated, remote attacker to alter access-device policies on the router by sending a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint. It carries a CVSS v3.1 base score of 9.1 (Critical), reflecting network-exploitable, no-authentication-required impact to confidentiality and integrity.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51708 – Unauthenticated WPS Configuration Tampering – TOTOLINK T6 Router Firmware 4.1.5cu.7

CVE-2026-51708 is an incorrect access control vulnerability (CWE-284) in the setWiFiWpsCfg function of the TOTOLINK T6 web management interface, firmware version 4.1.5cu.748_B20211015. The flaw allows a remote, unauthenticated attacker to change the device's WPS (Wi-Fi Protected Setup) availability by sending a crafted POST request to /cgi-bin/cstecgi.cgi. It carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51675 – Unauthenticated WAN Reconfiguration – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51675 is an incorrect access control vulnerability (CWE-284) in the setWanIeCfg function of the TOTOLINK T6 router's web management interface. Unauthenticated attackers can send a crafted POST request to /cgi-bin/cstecgi.cgi to reconfigure the device's WAN/uplink settings without providing credentials. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51674 – Unauthenticated Device Reboot via Access Control Bypass – TOTOLINK T6 (Firmware 4.1

CVE-2026-51674 is an incorrect access control vulnerability in the setScheduleCfg function of the /cgi-bin/cstecgi.cgi endpoint on TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. The endpoint fails to enforce authentication, allowing a remote, unauthenticated attacker to configure forced device reboot tasks. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-18765 – SQL Injection – Teracity E-OSB before V02.26.07.08.01

CVE-2026-18765 is a critical SQL injection vulnerability affecting Teracity Software Technologies Inc.'s E-OSB platform. The flaw arises from improper neutralization of special elements used in SQL commands (CWE-89), allowing an unauthenticated, remote attacker to inject and execute arbitrary SQL queries against the backend database. The issue has been assigned a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51669 – Unauthenticated Information Disclosure – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51669 is an incorrect access control vulnerability (CWE-284) in the getPairCfg function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated remote attacker can send a crafted POST request to the device's CGI endpoint to retrieve pairing and mesh-slave configuration data. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).

WATCH A SHORT IONIX DEMO

See how easy it is to implement a CTEM program with IONIX. Find and fix exploits fast.

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge