Description
Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated modification of parental‑control settings
Action: Patch Immediately
AI Analysis

Impact

The setParentalRules function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows an unauthenticated attacker to alter parental‑control settings by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This flaw permits the attacker to modify or bypass access restrictions applied to any user on the network, effectively altering the router’s security posture. The impact is a loss of confidentiality for traffic that should have been filtered or blocked, and the potential for denial‑of‑service if parental controls are disabled. The weakness is a classic improper access control issue (CWE‑284).

Affected Systems

The vulnerability affects the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or product variants are listed, restricting the scope to this specific configuration.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical severity. The EPSS score is less than 1%, suggesting a low likelihood of exploitation in the wild, but the absence of authentication means any device on the LAN can attempt it. Attack requires only sending a crafted HTTP POST request to /cgi-bin/cstecgi.cgi on the router’s web interface. Because the vulnerability is not listed in KEV, no known widespread exploitation is documented, yet the high severity and easy access warrant immediate attention.

Generated by OpenCVE AI on September 1, 2026 at 17:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest TOTOLINK firmware that addresses this issue
  • Restrict access to the router’s administrative interface by disabling WAN‑side access or using firewall rules to allow only trusted IP addresses
  • Disable parental‑control functionalities if they are not required to reduce the attack surface
  • Change the default administrator credentials to strong, unique passwords

Generated by OpenCVE AI on September 1, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Parental Control Bypass in TOTOLINK T6 Firmware

Tue, 01 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Parental Control Bypass in TOTOLINK T6 Firmware
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T13:22:36.868Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51710

cve-icon Vulnrichment

Updated: 2026-09-01T13:22:09.700Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T16:18:36.117

Modified: 2026-09-01T14:17:30.617

Link: CVE-2026-51710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T17:45:07Z

Weaknesses