Description
Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from incorrect access control in the delWiFiScheduleCfg function. An attacker who can reach the device over the network can send a crafted POST request to /cgi-bin/cstecgi.cgi and delete entries from the Wi‑Fi schedule. The flaw enables removal of scheduled network settings without any authentication. The impact is limited to loss of scheduled configurations and potential disruption of automated connections, but does not grant full control of the device or access to sensitive data.

Affected Systems

TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 is affected.

Risk and Exploitability

The CVSS score for this issue is not reported, and the EPSS score is unavailable. It is not listed in the CISA KEV catalog, but the lack of authentication required means the attack can be performed from any network host that can reach the device’s management interface. The vulnerability is exploitable via a simple HTTP POST, requiring no special privileges. Once exploited, only Wi‑Fi schedule entries can be removed, which could disrupt connectivity but does not expose broader system control.

Generated by OpenCVE AI on August 31, 2026 at 20:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest firmware from the vendor that addresses the schedule deletion flaw.
  • Restrict the management interface by allowing only trusted IP addresses or disable remote access if not necessary.
  • Monitor device logs and perform regular backups of configuration files to detect and recover from unauthorized schedule deletions.

Generated by OpenCVE AI on August 31, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Removal of Wi‑Fi Schedule via Incorrect Access Control in TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T19:07:49.926Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51732

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-31T20:17:04.460

Modified: 2026-08-31T20:59:32.817

Link: CVE-2026-51732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T20:30:05Z

Weaknesses