CVE-2026-51681
moderateUnauthenticated access-control flaw exposes WAN admin on TOTOLINK T6 routers
CVE-2026-51681 is an improper access-control flaw (CWE-284) in the setRemoteCfg function of the TOTOLINK T6 router's web management interface, reported against firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi that causes the router to enable WAN-side administration, making the management interface reachable from the internet. Because the CVSS score of 9.1 rates confidentiality and integrity impact as high with no privileges or user interaction required, successful abuse can lead to full administrative access to the device. Any TOTOLINK T6 unit running the cited firmware is affected, with units whose WAN interface accepts HTTP requests being the primary targets. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently assigns only about a 0.3% probability of exploitation within 30 days.
What to do: Check the firmware version on affected T6 units (visible on the device's status/admin page); if running 4.1.5cu.748_B20211015, apply the latest TOTOLINK firmware when released, since no fixed version is specified in the available data. As interim mitigations, disable or restrict remote/WAN administration and use firewall rules to limit access to the router's HTTP interface on the WAN side. Monitor logs for unauthenticated POST requests to /cgi-bin/cstecgi.cgi and verify that remote management settings have not been unexpectedly enabled.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (version cited in the report; whether other firmware versions are affected is not confirmed in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.