ZeroHour

CVE-2026-51674

moderate

Unauthenticated Access-Control Flaw in TOTOLINK T6 Router Enables Forced Reboots

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51674 is an incorrect access control flaw (CWE-284) in the setScheduleCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, with no credentials or user interaction required. Successful exploitation lets the attacker configure forced reboot tasks on the device, which can disrupt availability (e.g., reboot the router at will); the assigned CVSS 3.1 score of 9.8 rates the impact as high across confidentiality, integrity, and availability. Any TOTOLINK T6 router running the listed firmware is affected, particularly units whose web management interface is reachable from untrusted networks. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently puts 30-day exploitation probability at about 0.4%.

What to do: TOTOLINK T6 owners should check their running firmware version and apply the latest firmware from TOTOLINK when a patched build is released (no fixed version is listed yet). Until then, do not expose the router's web management interface to the internet and restrict access to /cgi-bin/cstecgi.cgi to trusted LAN clients. Look for unexpected scheduled reboot tasks or unexplained reboot loops as signs of tampering.

Affected
TOTOLINK T64.1.5cu.748_B20211015
Estimated exposure
moderatelikely on the order of thousands of installed devices (estimate; no public scan counts for this model) — Estimate based on TOTOLINK's consumer/SOHO router deployment patterns and the narrow affected set (a single model at one specific firmware build); no public internet-exposure scan counts were available for the T6.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.