ZeroHour

CVE-2026-51728

moderate

Unauthenticated firmware upload in TOTOLINK T6 router

CVSS 3.1
9.8 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-51728 is an incorrect access-control flaw (CWE-284) in the UploadFirmwareFile function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint, uploading a crafted firmware image without any credentials. Because the firmware-upload function performs no access control, a remote attacker who can reach the device's management interface can push modified firmware and gain full control of the router, driving the critical 9.8 CVSS score (high confidentiality, integrity, and availability impact). The flaw was confirmed in T6 firmware 4.1.5cu.748_B20211015; the available data does not confirm whether other TOTOLINK models or firmware builds are also affected. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is known, and EPSS estimates only a ~0.3% probability of exploitation in the next 30 days.

What to do: Check TOTOLINK T6 units for firmware version 4.1.5cu.748_B20211015 and apply a firmware update from TOTOLINK's support site when a fixed build is published. Until then, do not expose the router's management interface (and /cgi-bin/cstecgi.cgi) to the internet: disable WAN-side remote management and restrict access to the LAN or a management VLAN. No patch version is confirmed in the available data, so monitor the vendor's advisory for fixed firmware.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (firmware build cited in the report; other builds not confirmed)
Estimated exposure
moderatelikely on the order of a few thousand internet-exposed TOTOLINK T6 routers (brand-wide exposed TOTOLINK devices number in the tens of thousands) — Public internet scans typically show tens of thousands of exposed TOTOLINK devices across the brand, and the T6 is a single consumer model among many, so model-specific exposure is plausibly in the low thousands; exact T6 install counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.