CVE-2026-51710
nicheUnauthenticated access control flaw in TOTOLINK T6 parental controls
CVE-2026-51710 is an incorrect access control flaw (CWE-284) in the setParentalRules function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker triggers it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, requiring no credentials and no user interaction. Successful exploitation lets the attacker alter the device's parental-control behavior without authorization; the assigned CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) rates the issue critical at 9.1, with high confidentiality and integrity impact and no availability impact. Only TOTOLINK T6 devices on the reported firmware are affected, with greatest risk on units whose web management interface is reachable by attackers. No public proof-of-concept or in-the-wild exploitation is known; the flaw is not in CISA KEV and EPSS estimates only about a 0.3% probability of exploitation in the next 30 days.
What to do: TOTOLINK T6 owners should check the running firmware version and, if on 4.1.5cu.748_B20211015, check TOTOLINK's support site for a corrected firmware release (no fixed version is specified in the available data). Until patched, do not expose the router's management interface to the internet and restrict access to /cgi-bin/cstecgi.cgi to trusted networks. Administrators can also watch for unexpected changes to parental-control settings as a sign of probing or exploitation.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the firmware version named in the advisory; whether other builds are affected is not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.