ZeroHour

CVE-2026-51673

moderate

Unauthenticated NTP settings tampering in TOTOLINK T6 router firmware

CVSS 3.1
7.5 high
EPSS
<1%p26
Published
()
Modified
AI analysis

TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015 fails to enforce authentication on the setNtpCfg function of its web management interface, an improper access control issue (CWE-284). An unauthenticated attacker with network access to the management interface can send a crafted POST request to /cgi-bin/cstecgi.cgi and change the device's time synchronization (NTP) settings. Because the flaw carries only an integrity impact (CVSS 3.1 7.5, C:N/I:H/A:N), the attacker gains the ability to redirect time synchronization, for example by pointing the router at an attacker-controlled NTP server, rather than achieving code execution or data theft; tampered time settings can affect logging and any time-dependent behavior on the device. Any T6 unit running the affected firmware is exposed, most plausibly where the web management interface is reachable from an untrusted network or the internet. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.3% (26th percentile) probability of exploitation within 30 days.

What to do: Check whether your TOTOLINK T6 is running firmware 4.1.5cu.748_B20211015 and review the configured NTP servers for unexpected changes. Do not expose the web management interface (cstecgi.cgi) to the WAN; restrict it to a trusted LAN and disable remote/WAN-side management until TOTOLINK publishes a fixed firmware, since no patched version is specified in the available data.

Affected
TOTOLINK T6 router (firmware)4.1.5cu.748_B20211015
Estimated exposure
moderatelikely on the order of thousands to low tens of thousands of devices worldwide (single model, single 2021 firmware build; no official install base disclosed) — Estimated from TOTOLINK's footprint as a budget consumer/SOHO router brand that regularly appears in internet-wide scans at the tens-of-thousands level across all its models, scaled down to one model and one firmware build, with only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.