ZeroHour

CVE-2026-51657

moderate

Unauthenticated access control flaw exposes syslog config on TOTOLINK T6

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51657 is an incorrect access control flaw (CWE-284) in the getSyslogCfg function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated remote attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, requiring no credentials or user interaction. Successful exploitation lets the attacker retrieve syslog-related configuration from the device, potentially revealing logging destinations and network details; the assigned CVSS 3.1 score of 9.1 rates confidentiality and integrity impact as high even though the description frames the direct gain as access to this configuration. Affected parties are users of TOTOLINK T6 routers running the listed firmware version; no other models or versions are named in the available data. No public proof-of-concept or known exploitation exists at this time, with an EPSS of roughly 0.4% (30th percentile) and no CISA KEV listing.

What to do: Inventory any TOTOLINK T6 routers and check whether firmware 4.1.5cu.748_B20211015 is installed, then apply a fixed firmware from TOTOLINK when released (no fixed version is named in the current data). Until patching is possible, avoid exposing the router's web management interface to the internet, or restrict access to /cgi-bin/cstecgi.cgi to trusted sources only. No public PoC or in-the-wild exploitation is known, but TOTOLINK devices are routinely scanned by automated attackers, so prompt mitigation is still warranted for internet-facing units.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015
Estimated exposure
moderatelikely on the order of 1,000-10,000 internet-exposed T6 devices (estimated) — Public internet scan indexes (e.g., Shodan/FOFA) historically show tens of thousands of TOTOLINK routers exposed online across all models, and this specific model/firmware is plausibly a small fraction of that, but no T6-specific install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain syslog-related configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.