ZeroHour

CVE-2026-51694

Unauthenticated DHCP rule tampering in TOTOLINK T6 router

CVSS 3.1
7.5 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-51694 is an incorrect access control flaw (CWE-284) in the setStaticDhcpRules function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, which fails to require authentication before processing DHCP configuration requests. An attacker can trigger it by sending a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint over the network, with no credentials or user interaction required. A successful attack lets the attacker add or modify static DHCP rules, tampering with how the router assigns addresses to LAN clients; per the CVSS score the impact is limited to integrity (no data disclosure or crash), but altered DHCP rules can be used to steer or misdirect client traffic. Only TOTOLINK T6 units running the affected firmware are known to be impacted, with risk concentrated on routers whose web management interface is reachable from the internet or from untrusted LAN clients. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS assigns a low 0.3% probability of exploitation within 30 days.

What to do: Check TOTOLINK T6 units for the 4.1.5cu.748_B20211015 firmware version, review existing static DHCP rules for unauthorized entries, and apply a patched firmware from TOTOLINK when the vendor publishes a fix (no fixed version is specified in the available data). As an interim mitigation, restrict access to the router's management interface by disabling remote/WAN administration and limiting untrusted access on the LAN.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the firmware version confirmed affected; no broader version range provided in the available data)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.