ZeroHour

CVE-2026-51691

moderate

Unauthenticated Access-Control Flaw in TOTOLINK T6 Router Upload/Flash Handling

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51691 is an improper access control flaw (CWE-284) in the setUploadSetting function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's management endpoint /cgi-bin/cstecgi.cgi, reaching setUploadSetting without any credentials. By manipulating the upload or flash workflow, the attacker can invoke or alter upload/flash operations on the device, and the critical 9.8 CVSS 3.1 score indicates potentially high impact to confidentiality, integrity, and availability (e.g., unwanted firmware/upload actions or device disruption). Any administrator of a TOTOLINK T6 router on the affected firmware is exposed, especially units whose web management interface is reachable from untrusted networks. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at about 0.4%, so no exploitation is confirmed.

What to do: Check TOTOLINK's support site for a T6 firmware release newer than 4.1.5cu.748_B20211015 and upgrade when available, since no fixed version is specified in the available data. In the interim, restrict access to /cgi-bin/cstecgi.cgi to trusted management networks (e.g., disable WAN-side remote management and firewall the admin interface), and watch for unexpected upload or flash activity in device logs.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (version specifically cited; no broader affected or fixed version range provided in the data)
Estimated exposure
moderate≈10,000–100,000 internet- or LAN-exposed T6 routers (order-of-magnitude estimate; exact model counts unknown) — Public internet scans of TOTOLINK routers have historically shown tens of thousands of exposed devices brand-wide, and the T6 is one model within that consumer/SOHO installed base, so a five-figure exposure estimate is plausible but…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.