CVE-2026-51696
moderateUnauthenticated access-control flaw in TOTOLINK T6 exposes internal services
TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 does not properly enforce access control on the setPortForwardRules function of its web management interface. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi that invokes this function without logging in. By doing so, the attacker can create or alter port forwarding rules, making internal LAN services reachable from the wider network or the internet. Users running the cited firmware build are affected, especially where the router's web interface is reachable from the WAN; the flaw is rated 9.8 (critical) on CVSS 3.1. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days.
What to do: Check the router's firmware version; if it is 4.1.5cu.748_B20211015, disable or restrict WAN-side access to the management interface (including /cgi-bin/cstecgi.cgi) and audit existing port forwarding rules for unexpected entries. Watch TOTOLINK support channels for an updated firmware release, as no fixed version is named in the advisory.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the build cited in the advisory; whether other firmware builds are affected is not stated) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.