Description
Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted upload of custom CGI modules enabling remote code execution
Action: Apply Firmware Update
AI Analysis

Impact

A flaw in the UploadCustomModule routine of TOTOLINK T6 firmware allows an attacker to send a specially crafted POST request to /cgi-bin/cstecgi.cgi without authentication. Successfully exploiting the flaw results in the upload of a custom CGI module that runs with the privileges of the web server, giving the attacker the ability to execute arbitrary commands, exfiltrate data, or compromise the entire device. The core weakness is an improper restriction on who may upload modules, which can be leveraged to gain full control of the device. The impact is equivalent to remote code execution and can be used to persist malicious code or establish back‑doors.

Affected Systems

TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other vendor products are listed, but any device running this same firmware build shares the vulnerability.

Risk and Exploitability

The vulnerability is exploitable from any network the device exposes, and the attack does not require prior credentials. The CVSS score is 9.1 and the EPSS score is <1%, with the vulnerability not listed in the CISA KEV catalog. However, the nature of the bug—unauthenticated upload of executable content—makes it highly dangerous; an attacker who can reach the device could install malicious modules and maintain persistent access.

Generated by OpenCVE AI on September 3, 2026 at 14:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace the device firmware with a version that fixes the UploadCustomModule access control issue.
  • If an update is unavailable, disable the /cgi-bin/cstecgi.cgi upload endpoint or block it from external networks.
  • Configure network access controls to allow access to the endpoint only from trusted management IP addresses.
  • Monitor logs for unexpected POST requests to /cgi-bin/cstecgi.cgi and investigate immediately.

Generated by OpenCVE AI on September 3, 2026 at 14:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Upload of Custom CGI Modules via /cgi-bin/cstecgi.cgi

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Mon, 31 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Upload of Custom CGI Modules via /cgi-bin/cstecgi.cgi
Weaknesses CWE-284

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-02T16:03:14.334Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51723

cve-icon Vulnrichment

Updated: 2026-09-02T14:24:00.142Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T17:17:41.843

Modified: 2026-09-02T16:17:16.843

Link: CVE-2026-51723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T14:30:05Z

Weaknesses