CVE-2026-51660
largeUnauthenticated Access-Control Flaw Exposes IP/Port Filter Rules in TOTOLINK T6
CVE-2026-51660 is an improper access control flaw (CWE-284) in the getIpPortFilterRules function of the TOTOLINK T6 router's web management API, rated critical at CVSS 9.1. An unauthenticated attacker who can reach the router's admin interface sends a crafted POST request to /cgi-bin/cstecgi.cgi and obtains the device's IP and port filtering rules without any credentials or user interaction. The attacker gains disclosure of the router's filter configuration, revealing internal IPs and allowed/blocked ports that are useful for follow-up reconnaissance. Confirmed affected is the TOTOLINK T6 running firmware 4.1.5cu.748_B20211015, with exploitation possible wherever the admin CGI endpoint is network-reachable (WAN-exposed or LAN-adjacent). No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; the 0.4% EPSS (30th percentile) suggests low near-term exploitation likelihood.
What to do: Restrict the T6's web management interface to the LAN or trusted hosts (disable WAN-side HTTP management) so unauthenticated requests to /cgi-bin/cstecgi.cgi cannot reach getIpPortFilterRules. Check TOTOLINK's support site for a firmware update addressing this build; no fixed version is specified in available data. Review current IP and port filtering rules, since these are readable by unauthenticated users on reachable deployments.
| TOTOLINK T6 router (web management API /cgi-bin/cstecgi.cgi) | 4.1.5cu.748_B20211015 (other firmware builds unconfirmed in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.