Description
Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect access control flaw in the setWanIeCfg function of a TOTOLINK router. By sending a crafted POST request to /cgi-bin/cstecgi.cgi, an unauthenticated attacker can reconfigure the device's uplink settings. This unauthorized modification can lead to disruption of network connectivity, potential denial of service, or enable further compromise by altering routing behavior.

Affected Systems

The affected product is the TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015. No other vendors or products are listed. The scope is limited to this specific firmware build and device model.

Risk and Exploitability

The vulnerability does not have an EPSS score or CVSS score available, and it is not listed in CISA KEV. The exploit is a simple HTTP POST request that requires no authentication, making it trivially exploitable by anyone with network access to the router. Because the attacker can alter fundamental network settings, the risk to confidentiality, integrity, and availability is significant and should be treated as high.

Generated by OpenCVE AI on August 31, 2026 at 16:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a release that removes the vulnerable setWanIeCfg access path.
  • Configure the router’s firewall or access control lists to block or restrict access to /cgi-bin/cstecgi.cgi from untrusted networks.
  • Disable remote management features or limit them to trusted IP addresses to reduce the attack surface.

Generated by OpenCVE AI on August 31, 2026 at 16:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Reconfiguration of Uplink Settings via Incorrect Access Control in TOTOLINK T6 setWanIeCfg
Weaknesses CWE-284

Mon, 31 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T13:52:50.676Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51675

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-31T14:17:15.360

Modified: 2026-08-31T20:59:32.817

Link: CVE-2026-51675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:15:08Z

Weaknesses