Description
Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The setParentalRules function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows an unauthenticated attacker to alter parental‑control settings by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This flaw permits the attacker to modify or bypass access restrictions applied to any user on the network, effectively altering the router’s security posture. The impact is a loss of confidentiality for traffic that should have been filtered or blocked, and the potential for denial‑of‑service if parental controls are disabled. The weakness is a classic improper access control issue (CWE‑284).

Affected Systems

The vulnerability affects the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or product variants are listed, restricting the scope to this specific configuration.

Risk and Exploitability

No CVSS or EPSS score is provided, so the exact exploitation probability cannot be quantified. An attacker only needs to send an HTTP POST request to the router’s web interface, typically reachable on the LAN, to exploit the flaw. Because authentication is not required, any device connected to the local network could try the attack. While the vulnerability is not listed in the CISA KEV catalog, the lack of a KEV status does not mean it is benign; the exposure of the router’s administrative interface and the absence of authentication make the risk moderate to high, contingent on whether the interface is exposed externally or restricted to trusted devices.

Generated by OpenCVE AI on August 31, 2026 at 16:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest TOTOLINK firmware that addresses this issue
  • Restrict access to the router’s administrative interface by disabling WAN‑side access or using firewall rules to allow only trusted IP addresses
  • Disable parental‑control functionalities if they are not required to reduce the attack surface
  • Change the default administrator credentials to strong, unique passwords

Generated by OpenCVE AI on August 31, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Parental Control Bypass in TOTOLINK T6 Firmware
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T15:27:39.445Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51710

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T16:18:36.117

Modified: 2026-08-31T16:18:36.117

Link: CVE-2026-51710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:30:05Z

Weaknesses