CVE-2026-51698
moderateUnauthenticated access control flaw in TOTOLINK T6 router
CVE-2026-51698 is an improper access control flaw (CWE-284) in the setUrlFilterRules function of the TOTOLINK T6 router, running firmware 4.1.5cu.748_B20211015. An unauthenticated remote attacker can send a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint and modify URL filter rules without any credentials. Successful exploitation lets the attacker alter the device's browsing policies for the network it controls, and the 9.1 (critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N score reflects high confidentiality and integrity impact with no availability impact. Only TOTOLINK T6 units running the affected firmware are implicated by the available data, with exposure concentrated on routers whose web management interface is reachable from the internet. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates a 0.4% (30th percentile) chance of exploitation within 30 days.
What to do: Check TOTOLINK T6 units for firmware 4.1.5cu.748_B20211015 and watch for a patched release from TOTOLINK, since no fixed version is specified in the available data. As an interim mitigation, do not expose the router's web management interface (especially /cgi-bin/cstecgi.cgi) to the WAN or untrusted networks, and restrict administration to the LAN or a VPN. Review current URL filter rules for unexplained changes.
| TOTOLINK T6 router (setUrlFilterRules via /cgi-bin/cstecgi.cgi) | 4.1.5cu.748_B20211015 (the version cited in the advisory; the full range of affected versions is not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.