ZeroHour

CVE-2026-51713

Unauthenticated access-control flaw in TOTOLINK T6 router allows WAN dial manipulation

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-51713 is an incorrect access-control flaw (CWE-284) in the setManualDialCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker triggers it by sending a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint, invoking setManualDialCfg without any credentials. Successful exploitation allows the attacker to manipulate the router's WAN dial state, altering or disrupting how the device establishes its upstream connection; the flaw is scored critical (CVSS 3.1: 9.1) with network reachability and no privileges or user interaction required. Affected users are owners of TOTOLINK T6 routers, specifically those running the 4.1.5cu.748_B20211015 firmware named in the advisory. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a roughly 0.3% probability of exploitation within 30 days, so no active exploitation is known.

What to do: Check TOTOLINK T6 devices for firmware 4.1.5cu.748_B20211015 and upgrade via TOTOLINK's official support channels when a fixed release is published (no fixed version is specified in the available data). In the meantime, avoid exposing the router's web management interface or the /cgi-bin/cstecgi.cgi endpoint to untrusted networks such as the WAN, and disable remote administration if it is not needed. Monitor for unexpected WAN disconnects or dial-state changes, which could indicate exploitation attempts.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the only version named in the advisory; other versions not confirmed)
Estimated exposure
unknown — plausibly thousands to low tens of thousands of consumer units, but no public install-base or internet-exposure counts exist for this model — No active-install, market-share, or internet-scan counts are available for the TOTOLINK T6 specifically; the range is bounded by TOTOLINK's position as a budget consumer-router brand whose devices are typically deployed per household…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.