ZeroHour

CVE-2026-51717

large

Unauthenticated operating-mode change flaw in TOTOLINK T6 router

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-51717 is an improper access-control flaw (CWE-284) in the setOpModeCfg function of the TOTOLINK T6 router, firmware version 4.1.5cu.748_B20211015, which should require authentication but can be reached by anyone. It is triggered by sending a crafted, unauthenticated POST request to the router's web API endpoint /cgi-bin/cstecgi.cgi. A successful attacker can change the device's operating mode, and the CVSS 3.1 score of 9.1 (critical) reflects high confidentiality and integrity impact with no user interaction or privileges required. Only installations running the affected TOTOLINK T6 firmware are exposed, with the highest risk for units whose management interface is reachable from the internet. Exploitation status is currently quiet: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and apply TOTOLINK's next firmware release containing the fix once available (no fixed version is specified in the current data). Until then, do not expose the router's management web interface to the internet, and restrict or firewall unauthenticated access to /cgi-bin/cstecgi.cgi from untrusted networks.

Affected
TOTOLINK T6firmware 4.1.5cu.748_B20211015
Estimated exposure
largeon the order of tens of thousands of devices (single budget router model, based on TOTOLINK's consumer deployment footprint and routine internet exposure of… — Only the T6 model with the one listed firmware build is affected, but TOTOLINK consumer routers are widely deployed and their cstecgi.cgi web interface is commonly exposed to the internet, making a 10k-100k exposed-unit range a plausible…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.