Description
Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 gives attackers an unauthenticated window to probe the /cgi-bin/cstecgi.cgi endpoint. Because the weakness maps to CWE‑284 (Improper Access Control), the attacker can obtain cloud firmware check status information that may include device identifiers, firmware revision, and other operational details. This leakage compromises confidentiality but does not grant execution privileges or further control over the device.

Affected Systems

TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other vendors or products appear to be impacted according to the available data.

Risk and Exploitability

The EPSS score is missing and the vulnerability is not listed in CISA KEV. With no CVSS score presented, the formal severity remains unspecified. Nonetheless the remote, unauthenticated network‑based attack path through an HTTP POST request indicates a potentially high risk of information disclosure in environments where the router is exposed to untrusted networks. Monitoring and timely patching are recommended to mitigate the threat.

Generated by OpenCVE AI on August 29, 2026 at 00:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply TOTOLINK firmware updates that fix the improper access‑control flaw as soon as they are released.
  • Restrict outbound or inbound traffic to the /cgi-bin/cstecgi.cgi endpoint using firewall rules or ACLs, limiting access to approved internal networks.
  • If cloud firmware check is not required for your deployment, disable the feature through the router’s configuration menu.
  • Continuously monitor device logs for anomalous POST requests to /cgi-bin/cstecgi.cgi and set up alerts for suspicious activity.

Generated by OpenCVE AI on August 29, 2026 at 00:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T19:42:45.573Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51662

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:49.413

Modified: 2026-08-28T22:16:49.413

Link: CVE-2026-51662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:30:16Z

Weaknesses

No weakness.