CVE-2026-51713
Unauthenticated access-control flaw in TOTOLINK T6 router allows WAN dial manipulation
CVE-2026-51713 is an incorrect access-control flaw (CWE-284) in the setManualDialCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker triggers it by sending a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint, invoking setManualDialCfg without any credentials. Successful exploitation allows the attacker to manipulate the router's WAN dial state, altering or disrupting how the device establishes its upstream connection; the flaw is scored critical (CVSS 3.1: 9.1) with network reachability and no privileges or user interaction required. Affected users are owners of TOTOLINK T6 routers, specifically those running the 4.1.5cu.748_B20211015 firmware named in the advisory. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a roughly 0.3% probability of exploitation within 30 days, so no active exploitation is known.
What to do: Check TOTOLINK T6 devices for firmware 4.1.5cu.748_B20211015 and upgrade via TOTOLINK's official support channels when a fixed release is published (no fixed version is specified in the available data). In the meantime, avoid exposing the router's web management interface or the /cgi-bin/cstecgi.cgi endpoint to untrusted networks such as the WAN, and disable remote administration if it is not needed. Monitor for unexpected WAN disconnects or dial-state changes, which could indicate exploitation attempts.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (the only version named in the advisory; other versions not confirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.