Description
Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Device Clock Modification via Unauthenticated Access
Action: Immediate Patch
AI Analysis

Impact

In the TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015 the NTPSyncWithHost routine handles time synchronization without requiring proper authentication. This allows an attacker who can reach the device over the network to send a crafted HTTP POST to "/cgi-bin/cstecgi.cgi" and modify the internal system clock. The official description does not explicitly state additional consequences; however, based on the nature of a time change, it is inferred that time‑dependent functions on the device could be affected, though impacts on log integrity or certificate validation are not confirmed by the CVE data.

Affected Systems

The vulnerability is confined to TOTOLINK T6 routers running firmware build 4.1.5cu.748_B20211015. No other vendors or product versions are listed as impacted.

Risk and Exploitability

The flaw is an access control failure that can be exploited remotely via an unauthenticated web request. With a CVSS score of 9.1, this vulnerability falls into the critical severity range. While no EPSS score is available and the issue has not been added to the CISA KEV catalog, the absence of authentication means any host on the same network can alter the device clock. The potential for disruption combined with the simplicity of the attack vector suggests a high risk to devices that rely on accurate timekeeping.

Generated by OpenCVE AI on August 31, 2026 at 22:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by TOTOLINK that removes the NTPSyncWithHost vulnerability
  • If an update is not immediately available, restrict incoming traffic to the "/cgi-bin/cstecgi.cgi" endpoint by configuring local firewall rules or router ACLs to only allow traffic from trusted IP addresses
  • Disable or otherwise block the NTPSyncWithHost feature via router configuration, ensuring the device clock can only be set by authenticated management sessions

Generated by OpenCVE AI on August 31, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Time Synchronization Exploit in TOTOLINK T6 Router

Mon, 31 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Device Clock Modification via NTPSyncWithHost in TOTOLINK T6 4.1.5cu.748_B20211015
Weaknesses CWE-862

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Mon, 31 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Device Clock Modification via NTPSyncWithHost in TOTOLINK T6 4.1.5cu.748_B20211015
First Time appeared Totolink
Totolink t6
Weaknesses CWE-862
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T18:59:46.601Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51725

cve-icon Vulnrichment

Updated: 2026-08-31T18:59:42.548Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T18:17:18.197

Modified: 2026-08-31T20:59:32.817

Link: CVE-2026-51725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T23:00:12Z

Weaknesses