CVE-2026-51690
moderateUnauthenticated access-control flaw in TOTOLINK T6 lets attackers alter WAN settings
CVE-2026-51690 is an improper access-control flaw (CWE-284) in the setWanCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015, which performs WAN configuration changes without requiring authentication. An attacker triggers it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint with no credentials. Because the handler rewrites WAN settings, the attacker can alter the device's upstream provisioning and connectivity — for example changing WAN or DNS parameters — which can redirect traffic or break the internet link. Only TOTOLINK T6 units on the 4.1.5cu.748_B20211015 build are confirmed affected, and the risk is highest where the management interface is reachable from the WAN or from any unauthenticated LAN client. There is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.4% chance of exploitation within 30 days, so no exploitation is currently known.
What to do: Check TOTOLINK's support/downloads site for T6 firmware newer than 4.1.5cu.748_B20211015 and upgrade when a fix is published; no fixed version is given in the advisory data. In the meantime, do not expose the router's management interface to the internet, restrict /cgi-bin/cstecgi.cgi access to trusted LAN clients, and review current WAN and DNS settings for unauthorized changes.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (the only version named in the advisory; no other ranges specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.