ZeroHour

CVE-2026-51696

moderate

Unauthenticated access-control flaw in TOTOLINK T6 exposes internal services

CVSS 3.1
9.8 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 does not properly enforce access control on the setPortForwardRules function of its web management interface. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi that invokes this function without logging in. By doing so, the attacker can create or alter port forwarding rules, making internal LAN services reachable from the wider network or the internet. Users running the cited firmware build are affected, especially where the router's web interface is reachable from the WAN; the flaw is rated 9.8 (critical) on CVSS 3.1. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days.

What to do: Check the router's firmware version; if it is 4.1.5cu.748_B20211015, disable or restrict WAN-side access to the management interface (including /cgi-bin/cstecgi.cgi) and audit existing port forwarding rules for unexpected entries. Watch TOTOLINK support channels for an updated firmware release, as no fixed version is named in the advisory.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (the build cited in the advisory; whether other firmware builds are affected is not stated)
Estimated exposure
moderatelikely thousands of internet-exposed devices (single consumer model and firmware build cited; no public scan counts available) — Based on deployment patterns: TOTOLINK is a budget consumer/SOHO router vendor whose web UIs are commonly reachable from the WAN, but only one model and one firmware build are implicated, so the exposed share of its installed base is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.