ZeroHour

CVE-2026-51723

moderate

Unauthenticated custom module installation (incorrect access control) in TOTOLINK T6

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 fails to enforce access control on the UploadCustomModule function of its web management interface, allowing a custom CGI module to be installed without authentication. An unauthenticated remote attacker triggers the flaw by sending a crafted POST request to /cgi-bin/cstecgi.cgi. By installing an attacker-controlled custom module, the attacker gains control over the router's CGI handling, and the critical CVSS score with high confidentiality and integrity impact indicates this can result in full device compromise. Any TOTOLINK T6 running the listed firmware is affected, particularly units whose web management interface is reachable from the internet. No public proof-of-concept or in-the-wild exploitation is currently known, the flaw is not in CISA's KEV catalog, and EPSS puts near-term exploitation risk at about 0.3%.

What to do: Check the running firmware on any TOTOLINK T6 in your environment and upgrade to the latest firmware available from TOTOLINK (no fixed version is specified in this data). Until patched, avoid exposing the router's management interface to the internet (disable WAN-side web administration and related port forwarding) and restrict access to /cgi-bin/cstecgi.cgi to trusted sources. Also inspect the device for any unexpected custom modules already installed, which would indicate compromise.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the only version listed; other affected versions not specified in the data)
Estimated exposure
moderate≈1,000–10,000 internet-exposed T6 routers at most — No install or scan counts were provided, so the estimate assumes this single budget consumer router model accounts for only a small subset of the tens of thousands of TOTOLINK devices with internet-exposed /cgi-bin/cstecgi.cgi endpoints…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.