CVE-2026-51723
moderateUnauthenticated custom module installation (incorrect access control) in TOTOLINK T6
TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 fails to enforce access control on the UploadCustomModule function of its web management interface, allowing a custom CGI module to be installed without authentication. An unauthenticated remote attacker triggers the flaw by sending a crafted POST request to /cgi-bin/cstecgi.cgi. By installing an attacker-controlled custom module, the attacker gains control over the router's CGI handling, and the critical CVSS score with high confidentiality and integrity impact indicates this can result in full device compromise. Any TOTOLINK T6 running the listed firmware is affected, particularly units whose web management interface is reachable from the internet. No public proof-of-concept or in-the-wild exploitation is currently known, the flaw is not in CISA's KEV catalog, and EPSS puts near-term exploitation risk at about 0.3%.
What to do: Check the running firmware on any TOTOLINK T6 in your environment and upgrade to the latest firmware available from TOTOLINK (no fixed version is specified in this data). Until patched, avoid exposing the router's management interface to the internet (disable WAN-side web administration and related port forwarding) and restrict access to /cgi-bin/cstecgi.cgi to trusted sources. Also inspect the device for any unexpected custom modules already installed, which would indicate compromise.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (the only version listed; other affected versions not specified in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.