ZeroHour

CVE-2026-51677

large

Missing Access Control in TOTOLINK T6 Lets Anyone Toggle UPnP Settings

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-51677 is an incorrect access control flaw (CWE-284) in the setUPnPCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated remote attacker can trigger it by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint, which normally handles administrative configuration changes. Successful exploitation lets the attacker change the state of the router's UPnP service without any credentials; altering UPnP on an internet-facing router can create or modify port mappings that expose internal hosts to the internet, consistent with the 9.1 critical CVSS score (high confidentiality and integrity impact, no availability impact). Anyone operating a TOTOLINK T6 with the listed firmware, particularly units whose web management interface is reachable from the WAN, is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS currently estimates only a 0.3% probability of exploitation in the next 30 days, so no confirmed exploitation has been reported.

What to do: Check T6 units for firmware 4.1.5cu.748_B20211015 and apply TOTOLINK's patched firmware when released (no fixed version is specified in the available data). As an interim mitigation, do not expose the router's web management interface or /cgi-bin/cstecgi.cgi to the WAN, disable remote administration if it is not needed, and review UPnP settings for unexpected changes.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (only version listed as affected; no fixed version specified in the data)
Estimated exposure
largelikely on the order of 10,000–100,000 exposed T6 routers (order-of-magnitude estimate; no T6-specific install counts in the data) — Based on TOTOLINK's broad distribution of low-cost consumer routers and the routine appearance of TOTOLINK web management interfaces in public internet-exposure scans, though no T6-specific device or user counts are provided.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.