Description
Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect access control in the setOpModeCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015, enabling unauthenticated attackers to modify the device operating mode by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This flaw permits attackers to change operating mode without authentication, potentially leading to disruption of network services, unauthorized mode switching, or other configuration changes that affect network availability and integrity. The weakness corresponds to improper access controls (CWE-284).

Affected Systems

TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 are affected. The vendor is TOTOLINK and the specific firmware version is explicitly mentioned in the advisory. No additional product variants or versions are listed in the available data.

Risk and Exploitability

No publicly available CVSS or EPSS score is provided, and the vulnerability is not listed in CISA KEV, indicating no known exploitation at this time. The likely attack vector is remote; an attacker could craft a POST request over the local network or, if the interface is exposed externally, over the internet. The absence of exploitation evidence suggests a moderate risk for this flaw until an official firmware fix is released. Within the current dataset, the estimated exploitation likelihood cannot be quantified beyond its potential to allow unauthorized configuration changes.

Generated by OpenCVE AI on August 31, 2026 at 17:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest TOTOLINK T6 firmware that resolves the access control flaw.
  • If an upgrade is not yet available, restrict access to /cgi-bin/cstecgi.cgi so that only trusted local IP addresses can reach it, using firewall or ACL rules.
  • Alternatively, disable or block the cstecgi CGI endpoint through router configuration or network segmentation to prevent crafted POST requests from reaching the device.

Generated by OpenCVE AI on August 31, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Configuration Change in TOTOLINK T6 Router
Weaknesses CWE-284

Mon, 31 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device operating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T16:00:35.620Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51717

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T16:18:36.863

Modified: 2026-08-31T16:18:36.863

Link: CVE-2026-51717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T18:00:03Z

Weaknesses