Description
Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect access control check in the UploadFirmwareFile function permits an attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi on a TOTOLINK T6 router that is running firmware version 4.1.5cu.748_B20211015. Because the check is bypassed, an unauthenticated user can upload a malicious firmware image. Once the device accepts the image, the attacker gains complete control over the router, enabling arbitrary code execution, persistent compromise, or denial of service. The vulnerability forms the core of the device’s firmware update mechanism and therefore represents a high‑impact flaw.

Affected Systems

Devices built on the TOTOLINK T6 platform that are deployed with firmware 4.1.5cu.748_B20211015 are affected.

Risk and Exploitability

The flaw can be triggered over the network by any party that can reach the router’s HTTP interface, without credentials or authentication. Because the EPSS score is not available and the vulnerability is not listed in KEV, the exact exploitation probability is unknown, but the impact of successful exploitation is severe, providing full firmware replacement authority. Since the attack vector is purely remote and unauthenticated, defenders must treat the condition as a high‑risk exposure until a patch is applied or a mitigation is enforced.

Generated by OpenCVE AI on August 31, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to a version that addresses the access control flaw. If the manufacturer has released a fix, apply it immediately.
  • Block external access to /cgi-bin/cstecgi.cgi by configuring the router’s firewall, ACLs, or an upstream network device to reject all HTTP POST traffic to that endpoint.
  • Disable the firmware upload feature in the router’s configuration if an administrative setting exists; otherwise, physically prevent modification of the update mechanism through device isolation.
  • Continually monitor router logs for unexpected POST attempts to /cgi-bin/cstecgi.cgi and investigate any anomalies.

Generated by OpenCVE AI on August 31, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Firmware Upload Allowing Remote Code Execution on TOTOLINK T6 Devices
Weaknesses CWE-284

Mon, 31 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T17:18:12.517Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51728

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T18:17:18.543

Modified: 2026-08-31T18:17:18.543

Link: CVE-2026-51728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T19:00:04Z

Weaknesses