CVE-2026-51673
moderateUnauthenticated NTP settings tampering in TOTOLINK T6 router firmware
TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015 fails to enforce authentication on the setNtpCfg function of its web management interface, an improper access control issue (CWE-284). An unauthenticated attacker with network access to the management interface can send a crafted POST request to /cgi-bin/cstecgi.cgi and change the device's time synchronization (NTP) settings. Because the flaw carries only an integrity impact (CVSS 3.1 7.5, C:N/I:H/A:N), the attacker gains the ability to redirect time synchronization, for example by pointing the router at an attacker-controlled NTP server, rather than achieving code execution or data theft; tampered time settings can affect logging and any time-dependent behavior on the device. Any T6 unit running the affected firmware is exposed, most plausibly where the web management interface is reachable from an untrusted network or the internet. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.3% (26th percentile) probability of exploitation within 30 days.
What to do: Check whether your TOTOLINK T6 is running firmware 4.1.5cu.748_B20211015 and review the configured NTP servers for unexpected changes. Do not expose the web management interface (cstecgi.cgi) to the WAN; restrict it to a trusted LAN and disable remote/WAN-side management until TOTOLINK publishes a fixed firmware, since no patched version is specified in the available data.
| TOTOLINK T6 router (firmware) | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.