ZeroHour

CVE-2026-51661

moderate

Unauthenticated access-control flaw in TOTOLINK T6 exposes port-forwarding rules

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 contain an incorrect access control flaw (CWE-284) in the getPortForwardRules function of the web management API. An unauthenticated attacker with network access can send a crafted POST request to /cgi-bin/cstecgi.cgi and obtain the router's port-forwarding rules without any credentials or user interaction. The disclosure reveals which internal ports and services are exposed through forwarding, giving attackers reconnaissance detail that can guide targeted follow-on attacks; the flaw carries a critical CVSS 3.1 score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). Any T6 owner running the affected firmware is potentially affected, particularly where the management interface is reachable from the WAN or other untrusted networks. As of this analysis there is no known public proof of concept, the issue is not in CISA KEV, and EPSS estimates only about a 0.4% chance of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: No fixed firmware version is specified in the available data, so check TOTOLINK's support site for an updated T6 firmware before upgrading. In the meantime, prevent untrusted access to the router's web management interface (disable WAN-side remote management or firewall access to /cgi-bin/cstecgi.cgi) and review existing port-forwarding rules for anything sensitive. Given the critical severity, monitor for a public PoC, EPSS increases, or KEV listing.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (firmware)
Estimated exposure
moderate≈1k–10k internet-exposed devices (estimate; TOTOLINK routers collectively appear in the tens of thousands in public internet scans) — Only a single consumer model (T6) with one specific firmware is confirmed affected, while TOTOLINK devices across all models number in the tens of thousands in public scans, implying a likely footprint in the low thousands for this model.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.