ZeroHour

CVE-2026-51660

large

Unauthenticated Access-Control Flaw Exposes IP/Port Filter Rules in TOTOLINK T6

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51660 is an improper access control flaw (CWE-284) in the getIpPortFilterRules function of the TOTOLINK T6 router's web management API, rated critical at CVSS 9.1. An unauthenticated attacker who can reach the router's admin interface sends a crafted POST request to /cgi-bin/cstecgi.cgi and obtains the device's IP and port filtering rules without any credentials or user interaction. The attacker gains disclosure of the router's filter configuration, revealing internal IPs and allowed/blocked ports that are useful for follow-up reconnaissance. Confirmed affected is the TOTOLINK T6 running firmware 4.1.5cu.748_B20211015, with exploitation possible wherever the admin CGI endpoint is network-reachable (WAN-exposed or LAN-adjacent). No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; the 0.4% EPSS (30th percentile) suggests low near-term exploitation likelihood.

What to do: Restrict the T6's web management interface to the LAN or trusted hosts (disable WAN-side HTTP management) so unauthenticated requests to /cgi-bin/cstecgi.cgi cannot reach getIpPortFilterRules. Check TOTOLINK's support site for a firmware update addressing this build; no fixed version is specified in available data. Review current IP and port filtering rules, since these are readable by unauthenticated users on reachable deployments.

Affected
TOTOLINK T6 router (web management API /cgi-bin/cstecgi.cgi)4.1.5cu.748_B20211015 (other firmware builds unconfirmed in available data)
Estimated exposure
largetens of thousands of internet-exposed TOTOLINK T6 routers (order 10k-100k devices) — Public internet scans routinely index tens of thousands of TOTOLINK routers exposing their web admin CGI, and the T6 is among the brand's common models, though only WAN-reachable or LAN-adjacent instances can be exploited remotely.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.