Description
Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated alteration of storage configuration
Action: Restrict Endpoint
AI Analysis

Impact

The setStorageCfg function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an access control flaw that allows any unauthenticated client to send a crafted POST request to /cgi-bin/cstecgi.cgi and change storage‑related service settings. This flaw could let an attacker enable or disable persistent storage, alter data retention policies, or otherwise disrupt the device’s normal operation, impacting availability and potentially exposing stored data.

Affected Systems

This vulnerability affects TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. The specific affected component is the setStorageCfg routine exposed via the cstecgi CGI interface.

Risk and Exploitability

Because the flaw permits unauthenticated manipulation of the device’s configuration, an attacker can exploit it without needing prior credentials or special permissions, making deployment straightforward. The CVSS score of 9.8 and an EPSS score of <1% indicate a severe vulnerability that is unlikely to be widely exploited currently, but its impact remains significant. The vulnerability is not listed in CISA’s KEV catalog, so no publicly documented exploits are known at this time.

Generated by OpenCVE AI on September 3, 2026 at 14:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict network access to /cgi-bin/cstecgi.cgi by configuring router firewall rules so only trusted IP ranges can reach it.
  • Monitor device logs for unexpected POST requests to /cgi-bin/cstecgi.cgi and set up alerts for repeated attempts.
  • Check TOTOLINK’s official website or support channels regularly for firmware updates that address this vulnerability.

Generated by OpenCVE AI on September 3, 2026 at 14:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated access allows storage configuration alteration in TOTOLINK T6 devices

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 31 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated access allows storage configuration alteration in TOTOLINK T6 devices
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-02T16:03:55.236Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51684

cve-icon Vulnrichment

Updated: 2026-09-02T15:42:31.479Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T15:17:19.823

Modified: 2026-09-02T16:17:15.650

Link: CVE-2026-51684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:00:06Z

Weaknesses