CVE-2026-51694
—Unauthenticated DHCP rule tampering in TOTOLINK T6 router
CVE-2026-51694 is an incorrect access control flaw (CWE-284) in the setStaticDhcpRules function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, which fails to require authentication before processing DHCP configuration requests. An attacker can trigger it by sending a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint over the network, with no credentials or user interaction required. A successful attack lets the attacker add or modify static DHCP rules, tampering with how the router assigns addresses to LAN clients; per the CVSS score the impact is limited to integrity (no data disclosure or crash), but altered DHCP rules can be used to steer or misdirect client traffic. Only TOTOLINK T6 units running the affected firmware are known to be impacted, with risk concentrated on routers whose web management interface is reachable from the internet or from untrusted LAN clients. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS assigns a low 0.3% probability of exploitation within 30 days.
What to do: Check TOTOLINK T6 units for the 4.1.5cu.748_B20211015 firmware version, review existing static DHCP rules for unauthorized entries, and apply a patched firmware from TOTOLINK when the vendor publishes a fix (no fixed version is specified in the available data). As an interim mitigation, restrict access to the router's management interface by disabling remote/WAN administration and limiting untrusted access on the LAN.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (the firmware version confirmed affected; no broader version range provided in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.