Description
Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized guest network configuration
Action: Assess
AI Analysis

Impact

The vulnerability resides in the setWiFiEasyGuestCf function of the TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. Unauthorized users can send a specially crafted HTTP POST request to the /cgi-bin/cstecgi.cgi endpoint, triggering the function without authentication. The attacker can create new guest wireless access points or weaken existing guest network settings such as SSID, encryption type, or security key. Based on the description, it is inferred that these changes could allow an attacker or an outsider to connect to the guest network and potentially access internal resources through lateral movement or eavesdropping.

Affected Systems

The vulnerability is present in TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. Other devices in the same firmware family may also be affected if they ship with the same setWiFiEasyGuestCf implementation, which is an inference drawn from the firmware similarity.

Risk and Exploitability

The likely attack vector is a web‑based POST request that can be sent from any host able to reach the router’s admin interface, meaning the vulnerability is exploitable without credentials. The EPSS score of <1% indicates a very low probability of exploitation at present, but the CVSS score of 9.1 signals high severity. The flaw is not listed in the CISA KEV catalog, and no public exploit has been documented; however, the potential to alter guest network configuration in an unauthenticated manner warrants prompt assessment and mitigation.

Generated by OpenCVE AI on September 3, 2026 at 15:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from TOTOLINK that includes the patch for the setWiFiEasyGuestCf function.
  • If a patch is not available, restrict access to the router’s web administration interface to local IP addresses or VPN connections only, and block external traffic to /cgi-bin/cstecgi.cgi.
  • As a temporary countermeasure, disable the guest Wi‑Fi network entirely or limit its access before the patch is applied.

Generated by OpenCVE AI on September 3, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthorized guest wireless configuration via crafted POST request in TOTOLINK T6

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized guest wireless configuration via crafted POST request in TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-02T16:03:50.072Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51687

cve-icon Vulnrichment

Updated: 2026-09-02T15:31:05.763Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T15:17:20.110

Modified: 2026-09-02T16:17:15.833

Link: CVE-2026-51687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:00:08Z

Weaknesses