CVE-2026-51734
moderateUnauthenticated access-control flaw in TOTOLINK T6 router firmware
An improper access control issue (CWE-284) in the informSlaveUpdate function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows remote, unauthenticated attackers to invoke mesh slave update coordination. The flaw is triggered by sending a crafted POST request to the /cgi-bin/cstecgi.cgi management endpoint, with no credentials or user interaction required. A successful attacker can direct mesh slave update coordination on the device without authorization; the assigned CVSS 9.8 score (high confidentiality, integrity and availability impact) indicates the flaw is considered potentially severe, although no public proof-of-concept has yet confirmed weaponized impact. Any TOTOLINK T6 running the named firmware is affected, particularly units whose HTTP management interface is reachable from untrusted networks. Exploitation has not been reported to date: there is no public PoC, the flaw is not in CISA KEV, and EPSS currently estimates only a 0.4% probability of exploitation within 30 days.
What to do: Inventory TOTOLINK T6 devices and check firmware against version 4.1.5cu.748_B20211015; no fixed version is specified in the available data, so monitor TOTOLINK advisories and update as soon as patched firmware is released. Until then, restrict reachability of the web management interface (disable remote/WAN management or allowlist trusted source IPs) so unauthenticated POST requests to /cgi-bin/cstecgi.cgi cannot reach exposed units. Watch for unexpected mesh node update coordination activity as a possible indicator of exploitation attempts.
| TOTOLINK T6 router firmware | 4.1.5cu.748_B20211015 (the only version named in available data; other versions may also be affected but are not confirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.