Description
Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Internal Service Exposure via Unauthenticated Port Forwarding
Action: Patch
AI Analysis

Impact

The flaw in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 occurs in the setPortForwardRules function where an authentication check is omitted. An attacker can craft a POST request to /cgi-bin/cstecgi.cgi and create or modify forwarding entries, enabling the router to expose internal network services to the outside world. This improper access control (CWE‑284) directly compromises the confidentiality and integrity of internal resources.

Affected Systems

TOTOLINK’s T6 router running firmware version 4.1.5cu.748_B20211015 is the only product identified as vulnerable in the CVE record.

Risk and Exploitability

The high CVSS score of 9.8 reflects severe impact, yet the EPSS score of less than 1% suggests a low probability of real‑world exploitation. Because the vulnerability is not listed in CISA’s KEV catalog, no widespread exploitation has been observed. Based on the description, it is inferred that an unauthenticated attacker who can reach the router’s management interface—such as a user connected to the local network or an external party exploiting a exposed administrative port—can send the crafted POST request and create a port forwarding rule that exposes LAN services outside the network.

Generated by OpenCVE AI on September 2, 2026 at 05:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any TOTOLINK firmware update that addresses the setPortForwardRules access control flaw.
  • If no update is available, disable the port forwarding feature or remove the /cgi-bin/cstecgi.cgi endpoint from the router’s services.
  • Block external POST requests to /cgi-bin/cstecgi.cgi using a firewall or router access control lists.
  • Monitor router logs for unexpected use of the port forwarding API and investigate promptly.

Generated by OpenCVE AI on September 2, 2026 at 05:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Port Forwarding on TOTOLINK T6

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Port Forwarding on TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T14:13:44.680Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51696

cve-icon Vulnrichment

Updated: 2026-09-01T14:13:41.123Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T15:17:21.367

Modified: 2026-09-01T15:17:16.197

Link: CVE-2026-51696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T05:45:04Z

Weaknesses