ZeroHour

CVE-2026-51738

Broken access control in TOTOLINK T6 router enables unauthenticated reset and reboot

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51738 is an incorrect access-control flaw (CWE-284) in the LoadDefSettings function of the TOTOLINK T6 router's web management interface, scored critical at CVSS 3.1: 9.8. An unauthenticated attacker triggers it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, requiring no credentials or user interaction. The outcome is a reset of the device configuration to defaults plus a reboot, which disrupts connectivity and can be repeated at will; the CVSS vector scores the impact as high across confidentiality, integrity, and availability. Affected users are those running the T6 with firmware 4.1.5cu.748_B20211015, the build named in the advisory; whether other builds are affected is not documented in the available data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only a 0.4% probability of exploitation within 30 days.

What to do: No fixed firmware version is identified in the available data, so check TOTOLINK's support site for an updated T6 build. Until patched, keep the web management interface off the WAN and restrict access to trusted LAN clients, since the attack requires only unauthenticated HTTP reachability to the router. Treat unexpected factory-default resets or reboots as possible signs of exploitation and verify your running firmware version.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (the build named in the advisory; the full range of affected firmware is not documented in the provided data)
Estimated exposure
unknown — plausibly thousands to tens of thousands of devices given TOTOLINK's consumer-router footprint, but no T6-specific install-base or internet-exposure… — No install-base, market-share, or internet-scan counts for the T6 model are available in the source data, so any magnitude rests only on TOTOLINK's broad consumer/SOHO router deployment patterns and remains unverified.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.