Description
Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Access to Upgrade Status
Action: Patch Immediately
AI Analysis

Impact

TOTOLINK routers running firmware version 4.1.5cu.748_B20211015 contain a flaw in the getSlaveUpdate function of the /cgi-bin/cstecgi.cgi CGI that allows an unauthenticated attacker to send a crafted POST request. The vulnerability removes the access check that normally protects this endpoint, letting the attacker query the status of a slave upgrade and interfere with the upgrade bookkeeping process. The behavior can expose information about the device’s firmware state and potentially allow the attacker to disrupt future firmware updates by corrupting or bypassing upgrade tracking.

Affected Systems

The vulnerability affects TOTOLINK T6 routers that have firmware version 4.1.5cu.748_B20211015 installed. Only that firmware build is known to contain the flaw; other product families or firmware releases from TOTOLINK have not been reported to be impacted.

Risk and Exploitability

The CVSS score is 9.8, and EPSS is < 1%, indicating limited operational data. The vulnerability is not listed in the CISA KEV catalog. Attack requires a crafted POST to /cgi-bin/cstecgi.cgi and is only possible from an unauthenticated source that can reach the router’s management interface. While public exploit code is not available, the flaw can be used to gain significant knowledge of the upgrade environment and potentially disrupt firmware updates. The risk is considered low to moderate, but remediation should occur promptly when a patch is released.

Generated by OpenCVE AI on September 2, 2026 at 00:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from TOTOLINK that addresses the getSlaveUpdate access control flaw.
  • If a firmware update cannot be applied immediately, block or restrict access to /cgi-bin/cstecgi.cgi for the getSlaveUpdate operation using firewall rules or web server configuration.
  • Isolate the device from untrusted networks by implementing VLAN segmentation or placing the router in a separate management network.
  • Review device logs for anomalous POST requests to /cgi-bin/cstecgi.cgi and investigate any unauthorized activity.

Generated by OpenCVE AI on September 2, 2026 at 00:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Upgrade Status in TOTOLINK T6 Firmware

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Slave Upgrade Status in TOTOLINK T6 4.1.5cu.748_B20211015
Weaknesses CWE-200

Tue, 01 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Slave Upgrade Status in TOTOLINK T6 4.1.5cu.748_B20211015
Weaknesses CWE-200
CWE-284

Mon, 31 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T12:45:25.125Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51670

cve-icon Vulnrichment

Updated: 2026-09-01T12:45:19.995Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T14:17:14.533

Modified: 2026-09-01T13:19:43.510

Link: CVE-2026-51670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T00:45:04Z

Weaknesses