Description
Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized WAN dial configuration access
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an incorrect access control flaw in the setManualDialCfg function that allows an attacker to manipulate the WAN dial state without authentication. By sending a crafted POST request to /cgi-bin/cstecgi.cgi, an attacker who can reach the device over the network can change the dial state, effectively reconfiguring how the router connects to the internet. The flaw could enable an attacker to disrupt connectivity, bypass connectivity restrictions, or force the router to use an alternate service provider, thereby compromising availability and potentially confidentiality if related authentication mechanisms are weakened.

Affected Systems

The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendor or product variants are listed. The vulnerability is specific to this firmware release and affects all devices that have not applied the update that fixes the access control issue.

Risk and Exploitability

The attack vector is inferred to be through the exposed web interface, as the exploit requires sending a crafted POST request to the CGI script. The CVSS score is 9.1, indicating high severity. The EPSS score of less than 1% suggests a very low exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, because the flaw allows unauthenticated configuration changes, the risk is significant—any network user with access to the router’s management interface can reconfigure the WAN dial state. Mitigation requires patching or restricting the exposed interface.

Generated by OpenCVE AI on September 2, 2026 at 05:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest firmware that contains the fix for the access control issue.
  • Restrict the web management interface to trusted IP ranges or to the local network only.
  • Disable or remove the WAN dial function if it is unnecessary for your deployment.

Generated by OpenCVE AI on September 2, 2026 at 05:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in TOTOLINK T6 Manual Dial Configuration

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in TOTOLINK T6 Manual Dial Configuration
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T14:52:06.797Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51713

cve-icon Vulnrichment

Updated: 2026-09-01T14:51:30.242Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T16:18:36.430

Modified: 2026-09-01T15:17:17.237

Link: CVE-2026-51713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T05:15:05Z

Weaknesses