Description
Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain schedule or scheduled-reboot configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The flaw exists in the getScheduleCfg routine of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An attacker can trigger the routine by sending a crafted POST request to /cgi-bin/cstecgi.cgi, which returns schedule or scheduled‑reboot configuration details. Because authentication or access checks are missing, the device discloses sensitive configuration information, violating confidentiality. This is an information‑disclosure weakness classified as CWE‑284.

Affected Systems

The affected product is the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. No other firmware releases were identified as vulnerable. Only devices with this exact release are impacted.

Risk and Exploitability

The CVSS score is 4.3, an intermediate level that reflects potential disclosure without privilege requirements. The EPSS score is below 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV database. The likely attack vector is a network path that can reach the router’s web interface, such as a local LAN or an exposed Internet gateway. An attacker only needs to send the crafted HTTP POST to /cgi-bin/cstecgi.cgi, with no additional exploits or user interaction required, making the flaw straightforward to use in environments where the router is reachable from untrusted networks.

Generated by OpenCVE AI on September 2, 2026 at 07:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict access to the /cgi-bin/cstecgi.cgi endpoint with a firewall rule or the router’s ACL so that only trusted internal hosts can reach it.
  • Disable or remove remote management services that expose scheduling configuration when they are not needed, and enforce authentication on all management endpoints.
  • Apply any future firmware updates from TOTOLINK that address the getScheduleCfg access control flaw when available.

Generated by OpenCVE AI on September 2, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Retrieval of Scheduling Configuration in TOTOLINK T6 Router

Wed, 02 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control in TOTOLINK T6 4.1.5cu.748_B20211015 Exposes Schedule Configuration via Unauthenticated POST
Weaknesses CWE-200

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control in TOTOLINK T6 4.1.5cu.748_B20211015 Exposes Schedule Configuration via Unauthenticated POST
Weaknesses CWE-200
CWE-284

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain schedule or scheduled-reboot configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T17:31:48.906Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51654

cve-icon Vulnrichment

Updated: 2026-09-01T17:31:42.835Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T20:18:08.877

Modified: 2026-09-01T18:17:41.870

Link: CVE-2026-51654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T07:30:18Z

Weaknesses