Description
Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated weakening of router edge filtering
Action: Immediate Patch
AI Analysis

Impact

The setVpnPassCfg function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an incorrect access‑control check, letting any actor send a crafted POST request to /cgi-bin/cstecgi.cgi and alter edge‑filtering settings. The vulnerability does not allow code execution or full takeover; instead, it reduces the firewall’s effectiveness, potentially exposing internal devices to traffic that would normally be blocked or logged. The weakness is localized to the router’s administrative management interface and requires only network connectivity to the device.

Affected Systems

Affected system is the TOTOLINK T6 router running the 4.1.5cu.748_B20211015 firmware build. No other versions are listed, but any device using this firmware revision is included.

Risk and Exploitability

The security flaw permits unauthenticated manipulation of firewall rules through a simple HTTP POST, and the CVSS score of 9.8 indicates a high severity. The success probability is high for an attacker who can reach the device over the network. The EPSS score is below 1% and the issue is not listed in the CISA KEV catalog, but the lack of authentication control makes it a serious operational risk. An attacker could use the weakened edge filtering to pass malicious traffic or perform other network‑based attacks from within or outside the local network.

Generated by OpenCVE AI on September 2, 2026 at 05:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router to a firmware version that removes the missing access‑control check, as released by TOTOLINK.
  • Apply an access‑control rule or firewall rule that blocks or quarantines any traffic to /cgi-bin/cstecgi.cgi from unauthenticated sources.
  • Disable or tightly configure edge‑filtering manually, ensuring no unintended rules are enabled. Review the router’s security settings after any update or configuration change.

Generated by OpenCVE AI on September 2, 2026 at 05:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Weakening of Edge Filtering in TOTOLINK T6

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Weakening of Edge Filtering in TOTOLINK T6
Weaknesses CWE-284

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T14:17:06.633Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51693

cve-icon Vulnrichment

Updated: 2026-09-01T14:17:01.340Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T15:17:20.963

Modified: 2026-09-01T15:17:15.487

Link: CVE-2026-51693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T05:15:05Z

Weaknesses