Description
Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Patch Router
AI Analysis

Impact

The flaw is caused by an incorrect access control in the getCrpcConfig function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and obtain cloud remote‑control status and URL information, revealing sensitive configuration data that could be leveraged for further compromise.

Affected Systems

The vulnerability is documented only for TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other product or firmware versions are referenced in the advisory, so impact is limited to that specific model and build.

Risk and Exploitability

Authentication is not required, so any host that can reach the router’s web interface can trigger the vulnerability. The EPSS score is < 1%, KEV is not listed, and a CVSS score of 7.5 indicates a high‑risk exposure. The ease of exploitation and the disclosure of control‑related settings suggest that externally reachable routers are at elevated risk.

Generated by OpenCVE AI on September 2, 2026 at 05:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a version that includes the fix
  • If a newer firmware is not available, disable or restrict cloud‑control functionality through the router’s configuration
  • Use perimeter firewalls or access control lists to block external connections to /cgi‑bin/cstecgi.cgi or the router’s management interface and monitor for suspicious POST activity

Generated by OpenCVE AI on September 2, 2026 at 05:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title TOTOLINK T6 Cloud Remote-Control Status Disclosure via Unauthenticated POST

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title TOTOLINK T6 Cloud Remote-Control Status Disclosure via Unauthenticated POST
Weaknesses CWE-284

Fri, 28 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T16:01:54.228Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51644

cve-icon Vulnrichment

Updated: 2026-09-01T16:01:49.042Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T20:18:07.820

Modified: 2026-09-01T16:16:59.570

Link: CVE-2026-51644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T06:00:07Z

Weaknesses