Description
Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an incorrect access control flaw in the setManualDialCfg function that allows an attacker to manipulate the WAN dial state without authentication. By sending a crafted POST request to /cgi-bin/cstecgi.cgi, an attacker who can reach the device over the network can change the dial state, effectively reconfiguring how the router connects to the internet. The flaw could enable an attacker to disrupt connectivity, bypass connectivity restrictions, or force the router to use an alternate service provider, thereby compromising availability and potentially confidentiality if related authentication mechanisms are weakened.

Affected Systems

The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendor or product variants are listed. The vulnerability is specific to this firmware release and affects all devices that have not applied the update that fixes the access control issue.

Risk and Exploitability

The attack vector is inferred to be through the exposed web interface, as the exploit requires sending a POST request to a CGI script. No EPSS or CVSS scores are available, so the quantitative severity cannot be determined from the supplied data. The vulnerability is not listed in CISA's KEV catalog, indicating that no widespread known exploits have been reported. Nonetheless, because the flaw allows unauthenticated configuration changes, the risk is significant—any network user with access to the router’s management interface can execute the exploit. Mitigation requires patching or restricting the exposed interface.

Generated by OpenCVE AI on August 31, 2026 at 17:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest firmware that contains the fix for the access control issue.
  • Restrict the web management interface to trusted IP ranges or to the local network only.
  • Disable or remove the WAN dial function if it is unnecessary for your deployment.

Generated by OpenCVE AI on August 31, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in TOTOLINK T6 Manual Dial Configuration
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T15:55:08.281Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51713

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T16:18:36.430

Modified: 2026-08-31T16:18:36.430

Link: CVE-2026-51713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T17:30:03Z

Weaknesses