ZeroHour

CVE-2026-51679

large

Incorrect access control in TOTOLINK T6 allows unauthenticated admin takeover

CVSS 3.1
9.1 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 contains an improper access control flaw (CWE-284) in the setPasswordCfg function of its web management CGI. An unauthenticated remote attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to change the administrator account's credentials. Successful exploitation grants full administrative control of the router, letting the attacker alter its configuration, redirect traffic, or establish persistence. All TOTOLINK T6 units running the affected firmware are impacted, particularly those with the management interface reachable from the internet; the flaw is rated critical (CVSS 9.1). No public proof-of-concept or in-the-wild exploitation is currently known, and the EPSS score of 0.3% (28th percentile) suggests low near-term exploitation likelihood.

What to do: Check your T6 firmware version and update to the latest release from TOTOLINK when available (no fixed version is identified in the available data). Until patched, do not expose the router's web management interface to the internet; restrict it to the LAN or require VPN access. On affected devices, verify the administrator credentials have not been unexpectedly changed.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (other firmware versions not specified in available data)
Estimated exposure
largetens of thousands of internet-exposed TOTOLINK devices; T6-specific share unknown — Public internet-wide scans (e.g., Shodan/FOFA) regularly index tens of thousands of TOTOLINK routers with web management exposed, and the T6 is one of the vendor's widely distributed consumer models, but exact counts for T6 on this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.