CVE-2026-51701
largeUnauthenticated access-control bypass in TOTOLINK T6 router firmware
CVE-2026-51701 is an incorrect access-control flaw (CWE-284) in the setMacFilterRules function of the cstecgi.cgi web handler on TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi from any network that can reach the router's web management interface. Successful exploitation lets the attacker change the device's access-control settings (MAC filter rules), and the 9.1 CVSS score reflects high confidentiality and integrity impact with no availability impact. Any TOTOLINK T6 running the named firmware is affected, with the greatest risk on routers whose management interface is reachable from the WAN. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at 0.4% (30th percentile), so exploitation is not currently confirmed but unauthenticated bugs in internet-exposed routers are commonly targeted.
What to do: Check T6 routers for firmware 4.1.5cu.748_B20211015 and apply the latest firmware from TOTOLINK when a patched release is published (no fixed version is given in the available data). Until patched, restrict the router's web management interface (and /cgi-bin/cstecgi.cgi) to the LAN side, disable WAN-side/remote administration, and block unsolicited inbound access to the management port at the network edge. Monitor logs for unauthenticated POST requests to /cgi-bin/cstecgi.cgi invoking setMacFilterRules, and review existing MAC filter rules for unexpected changes.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (the build named in the advisory; affected range beyond this build is not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.