CVE-2026-51670
moderateUnauthenticated access control flaw in TOTOLINK T6 router firmware
CVE-2026-51670 is an improper access control flaw (CWE-284) in the getSlaveUpdate function of the TOTOLINK T6 router, documented against firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint to query the upgrade status of slave (mesh/extender) units and alter the upgrade bookkeeping state. The described practical impact is disclosure of slave upgrade status and interference with firmware-upgrade bookkeeping, although the assigned CVSS 3.1 base score is 9.8 (critical). Any TOTOLINK T6 administrator running the listed firmware is affected, with risk concentrated on devices whose web management interface is reachable from untrusted networks such as the WAN or a guest network. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates a 0.4% probability of exploitation within 30 days.
What to do: Check whether T6 units run firmware 4.1.5cu.748_B20211015 and check TOTOLINK's support/download site for a newer firmware release, as no fixed version is specified in the available data. Until a patch is applied, prevent the router's web management interface (including /cgi-bin/cstecgi.cgi) from being reachable from the internet by disabling WAN-side management or restricting access to trusted networks. No exploitation is currently known, so inventory and exposure reduction are the priority actions.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (only version documented as affected) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.