CVE-2026-51689
moderateUnauthenticated Access-Control Flaw in TOTOLINK T6 Firmware Upgrade Handler
CVE-2026-51689 is an improper access-control flaw (CWE-284) in the setUpgradeFW function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to invoke setUpgradeFW and trigger changes to the firmware-upgrade workflow without logging in. The critical CVSS 3.1 score of 9.1 reflects high integrity and availability impact with no confidentiality impact, indicating the attacker can manipulate the device's upgrade state or behavior rather than exfiltrate data. Any TOTOLINK T6 user running the listed firmware whose web management interface is reachable, especially from the internet, is potentially affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% probability of exploitation within 30 days, so no active exploitation is known.
What to do: Do not expose the T6 web management interface to untrusted networks such as the WAN or internet, since the flaw requires no authentication; keep it LAN-only or restrict access with firewall rules. Check the running firmware version on the device and apply a patched release when TOTOLINK publishes one (no fixed version is specified in the available data). As an interim mitigation, consider blocking unauthenticated POST requests to /cgi-bin/cstecgi.cgi from WAN-facing clients and monitor for vendor advisories.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the only firmware build listed; whether other versions are affected is not specified in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.