ZeroHour

CVE-2026-51725

large

Unauthenticated access-control flaw in TOTOLINK T6 router clock sync

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-51725 is an incorrect access control flaw (CWE-284) in the NTPSyncWithHost function of the TOTOLINK T6 router's web API, rated 9.1 (critical) on CVSS 3.1. An unauthenticated attacker triggers it by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint, which the device processes without requiring any credentials. Successful exploitation lets the attacker change the device's clock; the CVSS vector rates confidentiality and integrity impact as high with no availability impact, and clock manipulation can affect time-dependent behavior such as scheduled rules and logging. Only TOTOLINK T6 devices running firmware 4.1.5cu.748_B20211015 are named as affected in the available data. There is no known public PoC, the flaw is not in CISA KEV, and EPSS assigns a roughly 0.3% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Check T6 devices for firmware 4.1.5cu.748_B20211015 and upgrade to the newest T6 release published on TOTOLINK's support/download page once a fixed build is available (no fixed version is specified in the current data). As an interim mitigation, disable WAN-side remote management or restrict access to the router's web interface, including the /cgi-bin/cstecgi.cgi endpoint, to trusted hosts only. Monitor affected devices for unexpected clock changes or drift, which would indicate tampering.

Affected
TOTOLINK T64.1.5cu.748_B20211015
Estimated exposure
largeplausibly on the order of tens of thousands of internet-exposed or deployed T6 devices (estimate) — Public internet scans have repeatedly shown tens of thousands of TOTOLINK consumer routers exposing their cstecgi.cgi web API to the WAN, and the T6 is one of the brand's mass-market budget models, though only a subset of those devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.