Description
Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized removal of Wi‑Fi schedule entries
Action: Assess Impact
AI Analysis

Impact

This vulnerability arises from incorrect access control in the delWiFiScheduleCfg function. An attacker who can reach the device over the network can send a crafted POST request to /cgi-bin/cstecgi.cgi and delete entries from the Wi‑Fi schedule. The flaw enables removal of scheduled network settings without any authentication. The impact is limited to loss of scheduled configurations and potential disruption of automated connections, but does not grant full control of the device or access to sensitive data.

Affected Systems

TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 is affected.

Risk and Exploitability

The CVSS score for this issue is 5.3, and the EPSS score is < 1%. It is not listed in the CISA KEV catalog, but the lack of authentication required means the attack can be performed from any network host that can reach the device’s management interface. The vulnerability is exploitable via a simple HTTP POST, requiring no special privileges. Once exploited, only Wi‑Fi schedule entries can be removed, which could disrupt connectivity but does not expose broader system control.

Generated by OpenCVE AI on September 2, 2026 at 02:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest firmware from the vendor that addresses the schedule deletion flaw.
  • Restrict the management interface by allowing only trusted IP addresses or disable remote access if not necessary.
  • Monitor device logs and perform regular backups of configuration files to detect and recover from unauthorized schedule deletions.

Generated by OpenCVE AI on September 2, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Removal of Wi‑Fi Schedule via Incorrect Access Control in TOTOLINK T6

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Removal of Wi‑Fi Schedule via Incorrect Access Control in TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T15:48:40.781Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51732

cve-icon Vulnrichment

Updated: 2026-09-01T15:47:59.091Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T20:17:04.460

Modified: 2026-09-01T16:17:03.283

Link: CVE-2026-51732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:30:04Z

Weaknesses