ZeroHour

CVE-2026-51681

moderate

Unauthenticated access-control flaw exposes WAN admin on TOTOLINK T6 routers

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-51681 is an improper access-control flaw (CWE-284) in the setRemoteCfg function of the TOTOLINK T6 router's web management interface, reported against firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi that causes the router to enable WAN-side administration, making the management interface reachable from the internet. Because the CVSS score of 9.1 rates confidentiality and integrity impact as high with no privileges or user interaction required, successful abuse can lead to full administrative access to the device. Any TOTOLINK T6 unit running the cited firmware is affected, with units whose WAN interface accepts HTTP requests being the primary targets. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently assigns only about a 0.3% probability of exploitation within 30 days.

What to do: Check the firmware version on affected T6 units (visible on the device's status/admin page); if running 4.1.5cu.748_B20211015, apply the latest TOTOLINK firmware when released, since no fixed version is specified in the available data. As interim mitigations, disable or restrict remote/WAN administration and use firewall rules to limit access to the router's HTTP interface on the WAN side. Monitor logs for unauthenticated POST requests to /cgi-bin/cstecgi.cgi and verify that remote management settings have not been unexpectedly enabled.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (version cited in the report; whether other firmware versions are affected is not confirmed in the available data)
Estimated exposure
moderate≈1,000–10,000 internet-exposed T6 devices (estimate; no public per-model counts) — TOTOLINK devices routinely appear in public internet-wide scans in the tens of thousands and the T6 was a widely distributed budget mesh router, but no public per-model or per-firmware install counts exist, so the figure is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.