CVE-2026-51693
moderateUnauthenticated access-control flaw in TOTOLINK T6 router (CVE-2026-51693)
CVE-2026-51693 is an incorrect access control issue (CWE-284) in the setVpnPassCfg function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's management endpoint /cgi-bin/cstecgi.cgi, invoking the function without any credentials. By abusing this function, the attacker can modify VPN pass/filtering configuration and thereby weaken the device's edge filtering, which could ease follow-on attacks against the network; the CVSS 9.8 critical score reflects full network reachability with no privileges or user interaction required. Anyone operating a TOTOLINK T6 running the listed firmware is affected, particularly when the router's web management interface is reachable from the internet. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only about 0.3%, so no known exploitation has been reported.
What to do: Restrict access to the T6's web management interface (cstecgi.cgi) to trusted management networks and avoid exposing it directly to the internet; check the VPN pass/filtering configuration for unexpected changes. No fixed firmware version is identified in the available data, so monitor TOTOLINK for an advisory and upgrade promptly when a patched release is published.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the only firmware version cited in the data; whether other releases are affected is not stated) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.