Skip to main content

CVE-2026-11494

4.3
MEDIUMCVSS v3.1 Base Score
0.05%
LOW RiskEPSS (16th percentile)

A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least privilege violation. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

Published: 6/8/2026
Modified: 6/8/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CVSS v2 Score

4

AV:N/AC:L/Au:S/C:N/I:P/A:N

EPSS Score (Exploitation Probability)

0.05%LOW Exploitation Risk
16th percentile

This vulnerability has a 0.05% probability of being exploited in the next 30 days, ranking higher than 16% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-266, CWE-272)

CVE-2026-11497MEDIUM 5.3

A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

6/8/2026
CVE-2026-11492MEDIUM 4.3

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

6/8/2026
CVE-2026-10693MEDIUM 6.3

A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected.

6/3/2026
CVE-2026-48172CRITICAL 9.8

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.

5/21/2026
CVE-2026-7644HIGH 7.3

A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

5/2/2026

Similar SeverityMEDIUM