ZeroHour

CVE-2026-51675

moderate

Unauthenticated access-control flaw allows WAN uplink changes in TOTOLINK T6

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51675 is an incorrect access control flaw (CWE-284) in the setWanIeCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, reaching the setWanIeCfg handler without any login. Successful exploitation lets the attacker rewrite the device's WAN/uplink configuration — rated critical (CVSS 9.1, network vector, no privileges or user interaction required, high confidentiality and integrity impact) — potentially redirecting traffic or disrupting the affected network. Affected parties are owners and administrators of TOTOLINK T6 routers on the named firmware, particularly any unit whose web management interface is reachable by untrusted users. Exploitation status is quiet so far: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a low 0.4% probability of exploitation within 30 days (30th percentile).

What to do: Check TOTOLINK's support site for a firmware update addressing this issue, since no fixed version is stated in the available advisory data. As an interim mitigation, do not expose the router's web management interface to the internet (disable WAN-side remote administration and restrict admin access to trusted LAN hosts). Also review the router's current WAN/uplink configuration for signs of tampering, such as unexpected DNS or gateway settings.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the only version named in the advisory; whether other firmware versions are affected is not stated in the available data)
Estimated exposure
moderateon the order of a few thousand internet-exposed TOTOLINK T6 routers (est.; total retail deployments likely higher but uncounted) — TOTOLINK is a small budget consumer-router vendor whose models appear in public internet scans only in the low thousands across its entire catalog, and this flaw concerns a single model on a specific firmware, so exposed units are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.