ZeroHour

CVE-2026-51701

large

Unauthenticated access-control bypass in TOTOLINK T6 router firmware

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51701 is an incorrect access-control flaw (CWE-284) in the setMacFilterRules function of the cstecgi.cgi web handler on TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi from any network that can reach the router's web management interface. Successful exploitation lets the attacker change the device's access-control settings (MAC filter rules), and the 9.1 CVSS score reflects high confidentiality and integrity impact with no availability impact. Any TOTOLINK T6 running the named firmware is affected, with the greatest risk on routers whose management interface is reachable from the WAN. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at 0.4% (30th percentile), so exploitation is not currently confirmed but unauthenticated bugs in internet-exposed routers are commonly targeted.

What to do: Check T6 routers for firmware 4.1.5cu.748_B20211015 and apply the latest firmware from TOTOLINK when a patched release is published (no fixed version is given in the available data). Until patched, restrict the router's web management interface (and /cgi-bin/cstecgi.cgi) to the LAN side, disable WAN-side/remote administration, and block unsolicited inbound access to the management port at the network edge. Monitor logs for unauthenticated POST requests to /cgi-bin/cstecgi.cgi invoking setMacFilterRules, and review existing MAC filter rules for unexpected changes.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the build named in the advisory; affected range beyond this build is not specified in the available data)
Estimated exposure
largeplausibly tens of thousands of devices (estimate) — No vendor install counts or scan data accompany this advisory, but TOTOLINK is a mass-market consumer router vendor and home routers of this class are frequently deployed with their web management interface exposed to the internet, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.