Description
Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015 the NTPSyncWithHost routine handles time synchronization without requiring proper authentication. This allows an attacker who can reach the device over the network to send a crafted HTTP POST to "/cgi-bin/cstecgi.cgi" and modify the internal system clock. Such an unauthorized time change can undermine log integrity, certificate validation, scheduled tasks, and other time‑dependent functions on the device, potentially creating gaps in audit trails or enabling persistence operations that rely on altered timestamps.

Affected Systems

The vulnerability is confined to TOTOLINK T6 routers running firmware build 4.1.5cu.748_B20211015. No other vendors or product versions are listed as impacted.

Risk and Exploitability

The flaw is an access control failure that can be exploited remotely via an unauthenticated web request. While no EPSS score is available and the issue has not been added to the CISA KEV catalog, the absence of authentication means any host on the same network can alter the device clock. The potential for disruption combined with the simplicity of the attack vector suggests a high risk to devices that rely on accurate timekeeping.

Generated by OpenCVE AI on August 31, 2026 at 18:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by TOTOLINK that removes the NTPSyncWithHost vulnerability
  • If an update is not immediately available, restrict incoming traffic to the "/cgi-bin/cstecgi.cgi" endpoint by configuring local firewall rules or router ACLs to only allow traffic from trusted IP addresses
  • Disable or otherwise block the NTPSyncWithHost feature via router configuration, ensuring the device clock can only be set by authenticated management sessions

Generated by OpenCVE AI on August 31, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Mon, 31 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Device Clock Modification via NTPSyncWithHost in TOTOLINK T6 4.1.5cu.748_B20211015
First Time appeared Totolink
Totolink t6
Weaknesses CWE-862
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T18:59:46.601Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51725

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T18:17:18.197

Modified: 2026-08-31T19:16:49.700

Link: CVE-2026-51725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T18:30:03Z

Weaknesses