Description
Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Reconfiguration of Primary Wi‑Fi Settings
Action: Patch Firmware
AI Analysis

Impact

The flaw is an incorrect access control check in the setWiFiBasicCfg function, which allows an unauthenticated attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and change the primary Wi‑Fi configuration of a TOTOLINK T6 router. The impact is that the attacker can modify the SSID, security mode, or password, giving them full control over the wireless network, potentially diverting legitimate traffic, enabling man‑in‑the‑middle attacks, or causing denial of service by disabling the network. This weakness is identified as an improper authorization check (CWE‑284). The CVSS score of 9.8 categorises the vulnerability as critical.

Affected Systems

The vulnerability affects only TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other products or vendors are reported as impacted. The flaw resides in the router’s local management interface and is therefore limited to devices that expose that interface over a local or otherwise trusted network.

Risk and Exploitability

With a CVSS score of 9.8 the severity is critical, but the EPSS score of <1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploits. Based on the description it is inferred that the attack vector is an attacker who can reach the router’s management interface over the local or any network that can access that interface, and that the attacker need not authenticate to exploit the flaw. Therefore, the risk is high for any unprotected local or remote access to the management interface.

Generated by OpenCVE AI on September 1, 2026 at 17:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest TOTOLINK firmware that removes the insecure access control and fixes the POST endpoint vulnerability.
  • Disable remote management of the router and limit management access to a trusted local subnet or VPN.
  • Configure firewall or network segmentation rules to block outbound access to /cgi-bin/cstecgi.cgi and other management ports from untrusted or external networks.

Generated by OpenCVE AI on September 1, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Reconfiguration of Primary Wi‑Fi Settings via Insecure POST Endpoint

Tue, 01 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Reconfiguration of Primary Wi‑Fi Settings via Insecure POST Endpoint
Weaknesses CWE-284

Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T13:20:54.359Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51709

cve-icon Vulnrichment

Updated: 2026-09-01T13:20:50.269Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T16:18:36.010

Modified: 2026-09-01T14:17:30.127

Link: CVE-2026-51709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T17:45:07Z

Weaknesses