CVE-2026-51699
nicheUnauthenticated access-control flaw in TOTOLINK T6 exposes internal hosts via DMZ
CVE-2026-51699 is an incorrect access control issue (CWE-284) in the setDmzCfg function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, invoking setDmzCfg without any credentials. By altering the router's DMZ configuration, the attacker can expose an internal host behind the device to the wider internet, making otherwise hidden machines and services reachable; the flaw carries a critical CVSS 3.1 score of 9.8. Users running the named TOTOLINK T6 firmware are affected, especially installations where the router's web management interface is reachable from the WAN. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns only a 0.4% probability of exploitation within the next 30 days.
What to do: Do not expose the T6's web management interface (cstecgi.cgi) to the WAN, restrict access to trusted LAN clients, and review the current DMZ configuration for unexpected or unexplained entries. No fixed firmware version is named in the advisory, so check TOTOLINK for an updated release and apply it when available; until then, verify your running firmware version and monitor the vendor's advisories.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (the only version named in the advisory; other firmware versions may also be affected but are not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.