CVE-2026-51661
moderateUnauthenticated access-control flaw in TOTOLINK T6 exposes port-forwarding rules
TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 contain an incorrect access control flaw (CWE-284) in the getPortForwardRules function of the web management API. An unauthenticated attacker with network access can send a crafted POST request to /cgi-bin/cstecgi.cgi and obtain the router's port-forwarding rules without any credentials or user interaction. The disclosure reveals which internal ports and services are exposed through forwarding, giving attackers reconnaissance detail that can guide targeted follow-on attacks; the flaw carries a critical CVSS 3.1 score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). Any T6 owner running the affected firmware is potentially affected, particularly where the management interface is reachable from the WAN or other untrusted networks. As of this analysis there is no known public proof of concept, the issue is not in CISA KEV, and EPSS estimates only about a 0.4% chance of exploitation within 30 days, so no in-the-wild exploitation is currently known.
What to do: No fixed firmware version is specified in the available data, so check TOTOLINK's support site for an updated T6 firmware before upgrading. In the meantime, prevent untrusted access to the router's web management interface (disable WAN-side remote management or firewall access to /cgi-bin/cstecgi.cgi) and review existing port-forwarding rules for anything sensitive. Given the critical severity, monitor for a public PoC, EPSS increases, or KEV listing.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (firmware) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.