ZeroHour

CVE-2026-51699

niche

Unauthenticated access-control flaw in TOTOLINK T6 exposes internal hosts via DMZ

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51699 is an incorrect access control issue (CWE-284) in the setDmzCfg function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, invoking setDmzCfg without any credentials. By altering the router's DMZ configuration, the attacker can expose an internal host behind the device to the wider internet, making otherwise hidden machines and services reachable; the flaw carries a critical CVSS 3.1 score of 9.8. Users running the named TOTOLINK T6 firmware are affected, especially installations where the router's web management interface is reachable from the WAN. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns only a 0.4% probability of exploitation within the next 30 days.

What to do: Do not expose the T6's web management interface (cstecgi.cgi) to the WAN, restrict access to trusted LAN clients, and review the current DMZ configuration for unexpected or unexplained entries. No fixed firmware version is named in the advisory, so check TOTOLINK for an updated release and apply it when available; until then, verify your running firmware version and monitor the vendor's advisories.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the only version named in the advisory; other firmware versions may also be affected but are not specified)
Estimated exposure
nichelikely hundreds to low thousands of internet-exposed T6 units; exact install base unknown — TOTOLINK is a smaller SOHO/consumer router brand and the T6 is a single model, so this estimate is inferred from the brand's limited market presence rather than any published install counts or scan data for this specific model.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.