ZeroHour

CVE-2026-51734

moderate

Unauthenticated access-control flaw in TOTOLINK T6 router firmware

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

An improper access control issue (CWE-284) in the informSlaveUpdate function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows remote, unauthenticated attackers to invoke mesh slave update coordination. The flaw is triggered by sending a crafted POST request to the /cgi-bin/cstecgi.cgi management endpoint, with no credentials or user interaction required. A successful attacker can direct mesh slave update coordination on the device without authorization; the assigned CVSS 9.8 score (high confidentiality, integrity and availability impact) indicates the flaw is considered potentially severe, although no public proof-of-concept has yet confirmed weaponized impact. Any TOTOLINK T6 running the named firmware is affected, particularly units whose HTTP management interface is reachable from untrusted networks. Exploitation has not been reported to date: there is no public PoC, the flaw is not in CISA KEV, and EPSS currently estimates only a 0.4% probability of exploitation within 30 days.

What to do: Inventory TOTOLINK T6 devices and check firmware against version 4.1.5cu.748_B20211015; no fixed version is specified in the available data, so monitor TOTOLINK advisories and update as soon as patched firmware is released. Until then, restrict reachability of the web management interface (disable remote/WAN management or allowlist trusted source IPs) so unauthenticated POST requests to /cgi-bin/cstecgi.cgi cannot reach exposed units. Watch for unexpected mesh node update coordination activity as a possible indicator of exploitation attempts.

Affected
TOTOLINK T6 router firmware4.1.5cu.748_B20211015 (the only version named in available data; other versions may also be affected but are not confirmed)
Estimated exposure
moderatelikely tens of thousands of T6 units deployed, of which perhaps 1k-10k are internet-exposed (estimate) — No published install counts exist for this model; the estimate is derived from TOTOLINK's position as a widely deployed budget router/mesh brand and recurring public internet scans showing thousands of exposed TOTOLINK cstecgi.cgi…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.