CVE-2026-51684
nicheUnauthenticated Storage-Configuration Tampering in TOTOLINK T6 Router
CVE-2026-51684 is an improper access control flaw (CWE-284) in the setStorageCfg function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker on the network can send a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint and alter the state of the router's storage-related service without any credentials. Successful exploitation lets the attacker toggle or modify storage service configuration, which the assigned CVSS 3.1 score of 9.8 treats as fully impacting confidentiality, integrity, and availability. Only TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 are identified as affected in the available data. There is currently no known public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.4%, so exploitation has not been confirmed in the wild.
What to do: No patched firmware version is specified in the available data, so check TOTOLINK's support site for a T6 firmware update beyond 4.1.5cu.748_B20211015 and apply it when released. In the meantime, do not expose the router's web management interface to the internet (disable WAN-side HTTP/HTTPS management) so /cgi-bin/cstecgi.cgi is not reachable by unauthenticated remote users. Administrators should verify which TOTOLINK T6 units on their networks are running the affected build.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.