Description
Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain storage feature state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated information disclosure through improper access control
Action: Patch Now
AI Analysis

Impact

The total vulnerability arises from incorrect access control in the getStorageCfg function of the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An attacker who can reach the device can send a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint and receive the current storage feature state. This disclosure does not provide direct system compromise, but it exposes operational configuration that might aid further attacks. The weakness is a classic instance of CWE-284, improper access control, where a function does not enforce proper authentication before returning sensitive state data.

Affected Systems

The only affected product documented is the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. No other vendors or product lines are listed as impacted in the available data.

Risk and Exploitability

Because the flaw is triggered by an unauthenticated POST request to the publicly reachable /cgi-bin/cstecgi.cgi endpoint, the attack vector is network-based and does not require authentication or privileged credentials. The CVSS score is 4.3, the EPSS score is less than 1%, and the vulnerability is not reported in the CISA KEV catalog. The impact is the disclosure of the current storage feature state. While the disclosure does not directly facilitate system compromise, it could provide an attacker with configuration details that might be useful for planning further attacks, but no evidence indicates that it has been widely exploited in the wild.

Generated by OpenCVE AI on September 2, 2026 at 00:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the TOTOLINK T6 router firmware to the latest revision that addresses the getStorageCfg access control flaw
  • Restrict access to the /cgi-bin/cstecgi.cgi endpoint via firewall or ACLs to prevent unauthenticated POST requests
  • Monitor device logs for unexpected POST traffic to the cstecgi.cgi script and audit storage state exposure for anomalous activity

Generated by OpenCVE AI on September 2, 2026 at 00:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Retrieval of Storage Feature State via getStorageCfg Function in TOTOLINK T6
Weaknesses CWE-284

Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain storage feature state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T17:33:01.613Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51653

cve-icon Vulnrichment

Updated: 2026-09-01T17:32:54.906Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T20:18:08.770

Modified: 2026-09-01T18:17:41.707

Link: CVE-2026-51653

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T00:15:05Z

Weaknesses