CVE-2026-51728
moderateUnauthenticated firmware upload in TOTOLINK T6 router
CVE-2026-51728 is an incorrect access-control flaw (CWE-284) in the UploadFirmwareFile function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint, uploading a crafted firmware image without any credentials. Because the firmware-upload function performs no access control, a remote attacker who can reach the device's management interface can push modified firmware and gain full control of the router, driving the critical 9.8 CVSS score (high confidentiality, integrity, and availability impact). The flaw was confirmed in T6 firmware 4.1.5cu.748_B20211015; the available data does not confirm whether other TOTOLINK models or firmware builds are also affected. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is known, and EPSS estimates only a ~0.3% probability of exploitation in the next 30 days.
What to do: Check TOTOLINK T6 units for firmware version 4.1.5cu.748_B20211015 and apply a firmware update from TOTOLINK's support site when a fixed build is published. Until then, do not expose the router's management interface (and /cgi-bin/cstecgi.cgi) to the internet: disable WAN-side remote management and restrict access to the LAN or a management VLAN. No patch version is confirmed in the available data, so monitor the vendor's advisory for fixed firmware.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (firmware build cited in the report; other builds not confirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.