ZeroHour

CVE-2026-51670

moderate

Unauthenticated access control flaw in TOTOLINK T6 router firmware

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51670 is an improper access control flaw (CWE-284) in the getSlaveUpdate function of the TOTOLINK T6 router, documented against firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint to query the upgrade status of slave (mesh/extender) units and alter the upgrade bookkeeping state. The described practical impact is disclosure of slave upgrade status and interference with firmware-upgrade bookkeeping, although the assigned CVSS 3.1 base score is 9.8 (critical). Any TOTOLINK T6 administrator running the listed firmware is affected, with risk concentrated on devices whose web management interface is reachable from untrusted networks such as the WAN or a guest network. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates a 0.4% probability of exploitation within 30 days.

What to do: Check whether T6 units run firmware 4.1.5cu.748_B20211015 and check TOTOLINK's support/download site for a newer firmware release, as no fixed version is specified in the available data. Until a patch is applied, prevent the router's web management interface (including /cgi-bin/cstecgi.cgi) from being reachable from the internet by disabling WAN-side management or restricting access to trusted networks. No exploitation is currently known, so inventory and exposure reduction are the priority actions.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (only version documented as affected)
Estimated exposure
moderateroughly 1,000-10,000 devices (estimate; subset of TOTOLINK's internet-exposed fleet) — TOTOLINK budget routers are widely sold in emerging markets, but public internet scans typically show only thousands of TOTOLINK management interfaces exposed online, and the T6 is one model among many in that installed base, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.