CVE-2026-51717
largeUnauthenticated operating-mode change flaw in TOTOLINK T6 router
CVE-2026-51717 is an improper access-control flaw (CWE-284) in the setOpModeCfg function of the TOTOLINK T6 router, firmware version 4.1.5cu.748_B20211015, which should require authentication but can be reached by anyone. It is triggered by sending a crafted, unauthenticated POST request to the router's web API endpoint /cgi-bin/cstecgi.cgi. A successful attacker can change the device's operating mode, and the CVSS 3.1 score of 9.1 (critical) reflects high confidentiality and integrity impact with no user interaction or privileges required. Only installations running the affected TOTOLINK T6 firmware are exposed, with the highest risk for units whose management interface is reachable from the internet. Exploitation status is currently quiet: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and apply TOTOLINK's next firmware release containing the fix once available (no fixed version is specified in the current data). Until then, do not expose the router's management web interface to the internet, and restrict or firewall unauthenticated access to /cgi-bin/cstecgi.cgi from untrusted networks.
| TOTOLINK T6 | firmware 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.