Description
Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the UploadCustomModule routine of TOTOLINK T6 firmware allows an attacker to send a specially crafted POST request to /cgi-bin/cstecgi.cgi without authentication. Successfully exploiting the flaw results in the upload of a custom CGI module that runs with the privileges of the web server, giving the attacker the ability to execute arbitrary commands, exfiltrate data, or compromise the entire device. The core weakness is an improper restriction on who may upload modules, which can be leveraged to gain full control of the device. The impact is equivalent to remote code execution and can be used to persist malicious code or establish back‑doors.

Affected Systems

TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other vendor products are listed, but any device running this same firmware build shares the vulnerability.

Risk and Exploitability

The vulnerability is exploitable from any network the device exposes, and the attack does not require prior credentials. No CVSS or EPSS score is publicly available, and the vulnerability is not catalogued in the CISA KEV list. However, the nature of the bug—unauthenticated upload of executable content—makes it highly dangerous; an attacker who can reach the device could install malicious modules and maintain persistent access.

Generated by OpenCVE AI on August 31, 2026 at 18:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace the device firmware with a version that fixes the UploadCustomModule access control issue.
  • If an update is unavailable, disable the /cgi-bin/cstecgi.cgi upload endpoint or block it from external networks.
  • Configure network access controls to allow access to the endpoint only from trusted management IP addresses.
  • Monitor logs for unexpected POST requests to /cgi-bin/cstecgi.cgi and investigate immediately.

Generated by OpenCVE AI on August 31, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Upload of Custom CGI Modules via /cgi-bin/cstecgi.cgi
Weaknesses CWE-284

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T16:53:22.811Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51723

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T17:17:41.843

Modified: 2026-08-31T17:17:41.843

Link: CVE-2026-51723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T18:30:03Z

Weaknesses