ZeroHour

CVE-2026-51676

moderate

Unauthenticated Access Control Flaw in TOTOLINK T6 Router

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51676 is an incorrect access control issue (CWE-284) in the setAccessDeviceCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to the router's web API endpoint /cgi-bin/cstecgi.cgi without any login credentials, causing the device to accept and apply access-device configuration changes. As a result, an attacker can modify the router's access-device policies — the rules governing how connected devices are permitted to use the network — with the critical 9.1 CVSS score reflecting potentially high confidentiality and integrity impact. Only TOTOLINK T6 routers running the named firmware build are identified as affected in the available data. There is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS currently assigns it a 0.4% probability of exploitation within 30 days, so no exploitation has been confirmed.

What to do: Owners of TOTOLINK T6 routers should check their current firmware version on the admin interface and apply an updated firmware from TOTOLINK when one becomes available (no fixed version is specified in the current data). Until patching, disable remote/WAN-side management or restrict access to the router's web interface and the /cgi-bin/cstecgi.cgi endpoint to trusted networks only. Defenders managing fleets of TOTOLINK devices should watch for a vendor advisory confirming the fix and affected version range.

Affected
TOTOLINK T6 routerfirmware 4.1.5cu.748_B20211015 (other firmware versions are not confirmed in the available data)
Estimated exposure
moderatelikely on the order of 1,000–10,000 internet-exposed T6 routers (unknown share of the broader installed base) — TOTOLINK budget consumer/SOHO routers are widely deployed in Asian, Middle Eastern, and Latin American markets and public internet scans regularly surface tens of thousands of exposed TOTOLINK devices across all models, with a single model…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.