ZeroHour

CVE-2026-51668

moderate

Unauthenticated access-control flaw in TOTOLINK T6 router language settings

CVSS 3.1
7.5 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-51668 is an incorrect access-control issue (CWE-284) in the setLanguageCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's management endpoint /cgi-bin/cstecgi.cgi, with no credentials or user interaction required. The attacker gains the ability to modify the device's language configuration; per the CVSS scoring (C:N/I:H/A:N) the impact is to integrity only, with no direct confidentiality or availability loss, though it signals weak access control on the router's CGI management interface. Affected parties are operators of TOTOLINK T6 routers running the cited firmware, particularly units whose web management interface is reachable from the WAN side. As of publication there is no known exploitation: the flaw is not in CISA's KEV, no public PoC exists, and EPSS puts 30-day exploitation probability at roughly 0.3%.

What to do: Check whether TOTOLINK T6 devices in your estate run firmware 4.1.5cu.748_B20211015 and avoid exposing the router's web management interface (and /cgi-bin/cstecgi.cgi) to the WAN; disable remote management or restrict access to trusted management networks via firewall rules. No fixed firmware version is specified in the available data, so monitor TOTOLINK's support/download pages for a patched release before upgrading. Watch the dashboard for updates, as exploitation of this flaw class in TOTOLINK firmware has historically followed public PoC disclosure.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the version cited in the advisory; other firmware versions are not specified in the available data)
Estimated exposure
moderate≈1,000–10,000 internet-exposed TOTOLINK T6 routers (estimate; single model and cited firmware version) — Public internet-wide scans have historically shown TOTOLINK consumer routers in the tens of thousands with the /cgi-bin/cstecgi.cgi management endpoint exposed, and the T6 is one model within that lineup, so a low-thousands exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.