PT-2026-56965 · Totolink · Ac1200T10+6

·

CVE-2026-15271

·

Published

2026-07-09

·

Updated

2026-09-03

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A3000RU versions prior to 20260906 TOTOLINK A3100R versions prior to 20260906 TOTOLINK A950RG versions prior to 20260906 TOTOLINK AC1200T10 versions prior to 20260906 TOTOLINK CP450 versions prior to 20260906 TOTOLINK CS185R T10 versions prior to 20260906 TOTOLINK EX200 versions prior to 20260906
Description A least privilege violation exists in the Web Interface component due to an issue within the /etc/boa/boa.conf file. This flaw allows a remote attacker to manipulate the system, although the attack complexity is high and exploitation is considered difficult.
Recommendations Update TOTOLINK A3000RU to a version released after 20260906. Update TOTOLINK A3100R to a version released after 20260906. Update TOTOLINK A950RG to a version released after 20260906. Update TOTOLINK AC1200T10 to a version released after 20260906. Update TOTOLINK CP450 to a version released after 20260906. Update TOTOLINK CS185R T10 to a version released after 20260906. Update TOTOLINK EX200 to a version released after 20260906.

Fix

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15271

Affected Products

A3000Ru
A3100R
A950Rg
Ac1200T10
Cp450
Cs185R T10
Ex200