CVE-2026-51679
largeIncorrect access control in TOTOLINK T6 allows unauthenticated admin takeover
TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 contains an improper access control flaw (CWE-284) in the setPasswordCfg function of its web management CGI. An unauthenticated remote attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to change the administrator account's credentials. Successful exploitation grants full administrative control of the router, letting the attacker alter its configuration, redirect traffic, or establish persistence. All TOTOLINK T6 units running the affected firmware are impacted, particularly those with the management interface reachable from the internet; the flaw is rated critical (CVSS 9.1). No public proof-of-concept or in-the-wild exploitation is currently known, and the EPSS score of 0.3% (28th percentile) suggests low near-term exploitation likelihood.
What to do: Check your T6 firmware version and update to the latest release from TOTOLINK when available (no fixed version is identified in the available data). Until patched, do not expose the router's web management interface to the internet; restrict it to the LAN or require VPN access. On affected devices, verify the administrator credentials have not been unexpectedly changed.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (other firmware versions not specified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.