ZeroHour

CVE-2026-51705

moderate

Incorrect access control in TOTOLINK T6 router allows unauthenticated mesh renames

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 contain an incorrect access control flaw (CWE-284) in the setWiFiMeshName function of the device's web management interface. An unauthenticated attacker who can reach the router's management interface can send a crafted POST request to /cgi-bin/cstecgi.cgi and rename mesh entries without providing any credentials. Because the affected endpoint performs no authentication, any untrusted client with network access to the CGI handler can alter this configuration; the vendor-assigned CVSS 3.1 score of 9.8 (critical) assumes high confidentiality, integrity, and availability impact, though the published description specifically documents the ability to rename mesh entries. All T6 units running the listed firmware are affected, with risk concentrated on routers whose management interface is reachable from the WAN or an untrusted network. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates a 0.4% probability of exploitation within 30 days.

What to do: Inventory TOTOLINK T6 devices and check the running firmware version; units on 4.1.5cu.748_B20211015 should be treated as affected. Until a vendor patch is published (no fixed version is specified in the available data), restrict the web management interface by disabling WAN-side/remote management and limiting access to trusted sources, and monitor TOTOLINK's support site for a fixed firmware release.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (the version cited in the advisory; no broader affected range is specified)
Estimated exposure
moderateon the order of thousands of devices (estimated; no model-specific install-base or scan figures are public) — No public install-base data exists for the T6 model specifically, so the estimate reflects TOTOLINK's consumer/SOHO router footprint and the fact that TOTOLINK devices are commonly observed as internet-exposed in public scans, narrowed to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.