ZeroHour

CVE-2026-51740

moderate

Unauthenticated access-control flaw lets attackers kill services on TOTOLINK T6

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51740 is an incorrect access control flaw (CWE-284) in the killProcess function of TOTOLINK T6 router firmware, with the affected build identified as 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, invoking killProcess without any authentication or authorization checks. Successful exploitation allows the attacker to terminate critical services running on the device, resulting in a denial-of-service condition on the router (CVSS 3.1: 9.8, network vector with high availability impact). Only TOTOLINK T6 devices running the affected firmware are known to be impacted, with home and small-office users of this budget router model constituting the population at risk. No public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS assigns roughly a 0.4% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Update T6 firmware to the latest build published by TOTOLINK, since the advisory does not specify a fixed version. Until patching, do not expose the router's management interface to the WAN and restrict access to /cgi-bin/cstecgi.cgi to trusted LAN clients. If services are terminated, a reboot of the device restores them.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the firmware build confirmed in the advisory; whether other builds are affected is not stated)
Estimated exposure
moderateon the order of thousands to tens of thousands of deployed T6 devices, of which likely only a few thousand are internet-exposed — Estimated from TOTOLINK's profile as a high-volume budget consumer router brand with the T6 among its mainstream models, combined with typical internet-wide scan results that show only a few thousand exposed units for any single TOTOLINK…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.