Description
Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of static DHCP rules
Action: Update firmware
AI Analysis

Impact

A flaw in the setStaticDhcpRules function of TOTOLINK firmware T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The vulnerability is an incorrect access control restriction violation (CWE‑284). It grants attackers the ability to alter the DHCP configuration that devices use to obtain IP addresses, enabling unauthorized changes to network address assignments.

Affected Systems

Devices running TOTOLINK firmware T6 4.1.5cu.748_B20211015 are impacted. The flaw exists in the setStaticDhcpRules functionality accessed via the /cgi-bin/cstecgi.cgi endpoint.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity issue. The EPSS score is less than 1 %, suggesting a low probability of active exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers exploit the flaw by issuing a specially crafted HTTP POST request to /cgi-bin/cstecgi.cgi without authentication, a likely web‑based attack vector. Successful exploitation results in unauthorized modification of DHCP settings, directly impacting network configuration control.

Generated by OpenCVE AI on September 2, 2026 at 07:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update that contains the access‑control fix
  • If a firmware update is not yet available, block or restrict access to /cgi-bin/cstecgi.cgi using firewall rules
  • Continuously monitor DHCP configuration files or logs for unexpected changes and inspect POST traffic to the CGI endpoint

Generated by OpenCVE AI on September 2, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Modification of Static DHCP Rules

Wed, 02 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Control Issue Allows Modification of Static DHCP Rules
Weaknesses CWE-285

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Control Issue Allows Modification of Static DHCP Rules
Weaknesses CWE-285

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T14:16:16.679Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51694

cve-icon Vulnrichment

Updated: 2026-09-01T14:16:11.520Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T15:17:21.090

Modified: 2026-09-01T15:17:15.710

Link: CVE-2026-51694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T08:00:14Z

Weaknesses