ZeroHour

CVE-2026-51689

moderate

Unauthenticated Access-Control Flaw in TOTOLINK T6 Firmware Upgrade Handler

CVSS 3.1
9.1 critical
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-51689 is an improper access-control flaw (CWE-284) in the setUpgradeFW function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to invoke setUpgradeFW and trigger changes to the firmware-upgrade workflow without logging in. The critical CVSS 3.1 score of 9.1 reflects high integrity and availability impact with no confidentiality impact, indicating the attacker can manipulate the device's upgrade state or behavior rather than exfiltrate data. Any TOTOLINK T6 user running the listed firmware whose web management interface is reachable, especially from the internet, is potentially affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% probability of exploitation within 30 days, so no active exploitation is known.

What to do: Do not expose the T6 web management interface to untrusted networks such as the WAN or internet, since the flaw requires no authentication; keep it LAN-only or restrict access with firewall rules. Check the running firmware version on the device and apply a patched release when TOTOLINK publishes one (no fixed version is specified in the available data). As an interim mitigation, consider blocking unauthenticated POST requests to /cgi-bin/cstecgi.cgi from WAN-facing clients and monitor for vendor advisories.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (the only firmware build listed; whether other versions are affected is not specified in the data)
Estimated exposure
moderatelikely on the order of several thousand to tens of thousands of deployed T6 units (exact install-base and internet-exposure counts are not public) — No public scan counts or install-base figures exist for this specific TOTOLINK T6 firmware build, so the estimate is an order-of-magnitude judgment based on TOTOLINK's footprint as a budget consumer/SOHO router brand whose models routinely…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.