CVE-2026-51674
moderateUnauthenticated Access-Control Flaw in TOTOLINK T6 Router Enables Forced Reboots
CVE-2026-51674 is an incorrect access control flaw (CWE-284) in the setScheduleCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, with no credentials or user interaction required. Successful exploitation lets the attacker configure forced reboot tasks on the device, which can disrupt availability (e.g., reboot the router at will); the assigned CVSS 3.1 score of 9.8 rates the impact as high across confidentiality, integrity, and availability. Any TOTOLINK T6 router running the listed firmware is affected, particularly units whose web management interface is reachable from untrusted networks. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently puts 30-day exploitation probability at about 0.4%.
What to do: TOTOLINK T6 owners should check their running firmware version and apply the latest firmware from TOTOLINK when a patched build is released (no fixed version is listed yet). Until then, do not expose the router's web management interface to the internet and restrict access to /cgi-bin/cstecgi.cgi to trusted LAN clients. Look for unexpected scheduled reboot tasks or unexplained reboot loops as signs of tampering.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.