Sceawere

Vulnerability Detail

CVE-2026-51674UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Improper Access Control

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-31T14:17:15.197Z",
  "pubdate": "2026-08-31T14:17:15.197Z",
  "executiveSummary": "The TOTOLINK T6 router, specifically firmware version 4.1.5cu.748_B20211015, contains a critical improper access control vulnerability within its web management interface.\nThe flaw resides in the setScheduleCfg function, which fails to enforce mandatory authentication checks when processing administrative requests.\nThis vulnerability allows unauthenticated, remote attackers to interact with the device's configuration backend via the /cgi-bin/cstecgi.cgi endpoint.\nBy submitting a specially crafted POST request, an attacker can manipulate schedule settings, specifically enabling or configuring forced reboot tasks.\nThe potential impact includes denial-of-service conditions through repeated, unauthorized reboots, which can disrupt critical network operations and facilitate persistence or further exploitation attempts.\nThe vulnerability does not require prior user credentials or administrative privileges, making it highly accessible to any attacker with network connectivity to the device's web management interface.",
  "technicalDetails": "The vulnerability is rooted in a failure of the access control mechanism within the setScheduleCfg function, which is reachable via the common gateway interface at /cgi-bin/cstecgi.cgi.\nIn the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015, the application logic responsible for handling schedule-related configuration requests does not perform adequate session validation or authorization checks before committing changes to the device's non-volatile memory or active configuration runtime.\nThe attack flow begins when an unauthenticated attacker sends a maliciously crafted HTTP POST request to /cgi-bin/cstecgi.cgi. Because the application fails to verify the presence of a valid session token or authentication cookie, the web server executes the command associated with the setScheduleCfg function.\nThe payload of the POST request is designed to mimic the structure of a legitimate configuration update, specifically targeting parameters related to automated system reboots. Upon successful processing by the backend CGI script, the router accepts the malicious configuration parameters, allowing the attacker to define arbitrary reboot schedules.\nThis configuration change is processed without further validation, effectively bypassing the security boundary intended to protect administrative functions from unauthorized access. The vulnerable component acts as a sink for external input that is never sanitized or authenticated, allowing for the direct modification of the device's operational state.\nThe exploitation is trivial, as it does not require complex heap manipulation or memory corruption, but rather exploits a logical flaw in the administrative authentication flow. The network exposure is limited to the interface hosting the web management service, typically accessible over the local area network or, if misconfigured, the wide area network.\nPost-exploitation impact includes the ability to perform a permanent or recurring denial-of-service attack on the target device. By programming forced reboots, an attacker can effectively disable the network, terminate active connections, and potentially interrupt security monitoring or logging processes that rely on stable device uptime. This control over reboot scheduling also provides a mechanism for the attacker to repeatedly cycle the power state, which may be leveraged to bypass certain memory-resident security protections or force the device into a state that is more susceptible to secondary exploitation vectors."
}
CVE-2026-51674: TOTOLINK T6 Improper Access Control (CRITICAL Severity, CVSS: 9.8) - Sceawere