Description
Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure (Internal Host Exposure)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the setDmzCfg function of the TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An incorrect access control check allows an attacker who can send a crafted POST request to /cgi-bin/cstecgi.cgi to expose an internal host without needing authentication. The primary impact is the disclosure of internal host information, which can be used for network reconnaissance or as a foothold for further attacks. The weakness maps to the improper access control category identified as CWE‑284.

Affected Systems

The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No additional affected versions are listed in the CVE metadata, and the vendor is identified only as TOTOLINK. The flaw is located in the setDmzCfg function reachable via the /cgi-bin/cstecgi.cgi path.

Risk and Exploitability

The CVE has a CVSS score of 9.8, indicating critical severity, and an EPSS score of < 1%; it is not included in the CISA KEV catalog. Based on the description, the attack vector is remote; any network‑connected attacker can craft the POST request without authentication, making exploitation relatively straightforward. Because the flaw leads to internal host exposure, it poses critical risk for routers that are not otherwise protected. No special exploitation conditions are cited, so the vulnerability can affect all devices running the specified firmware without additional prerequisites.

Generated by OpenCVE AI on September 2, 2026 at 05:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check TOTOLINK for an updated firmware or patch that fixes the setDmzCfg access control issue.
  • If an update is unavailable, disable the DMZ functionality or the setDmzCfg endpoint to prevent unauthenticated access.
  • Implement network segmentation or firewall rules to block external access to the router’s /cgi-bin/cstecgi.cgi endpoint.

Generated by OpenCVE AI on September 2, 2026 at 05:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Host Exposure via Improper Access Control in TOTOLINK T6 setDmzCfg

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Host Exposure via Improper Access Control in TOTOLINK T6 setDmzCfg
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T14:10:54.863Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51699

cve-icon Vulnrichment

Updated: 2026-09-01T14:10:50.954Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T16:18:35.037

Modified: 2026-09-01T15:17:16.810

Link: CVE-2026-51699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T05:15:05Z

Weaknesses