Sceawere

Vulnerability Detail

CVE-2026-51677UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 UPnP Access Control

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-31T14:17:15.697Z",
  "pubdate": "2026-08-31T14:17:15.697Z",
  "executiveSummary": "This vulnerability involves an incorrect access control flaw within the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015.\nThe issue manifests as an authorization bypass, allowing unauthenticated remote attackers to manipulate the Universal Plug and Play (UPnP) service state.\nThe vulnerability resides in the setUPnPCfg function, which fails to enforce proper authentication checks before executing state-changing commands requested via the /cgi-bin/cstecgi.cgi endpoint.\nSuccessful exploitation allows unauthorized third parties to modify critical network configuration settings, potentially exposing the internal network to external threats or disrupting service connectivity.\nThe attack requires no prior authentication, significantly lowering the barrier for exploitation by remote actors with network access to the device management interface.\nThe risk implication is high, as the ability to arbitrarily toggle UPnP settings can be leveraged to facilitate NAT traversal for malicious traffic, bypassing perimeter security controls.",
  "technicalDetails": "The vulnerability is localized within the setUPnPCfg function, a backend routine responsible for handling Universal Plug and Play configuration state management.\nThe affected component is the cgi-bin handler, specifically /cgi-bin/cstecgi.cgi, which serves as a primary interface for administrative actions in the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015.\nRoot Cause Analysis: The underlying issue is an insufficient access control check within the implementation of the setUPnPCfg function. The function executes POST requests intended for system configuration without verifying the session token or authentication credentials of the requesting entity.\nAttack Flow: An attacker initiates the exploitation by crafting a malicious HTTP POST request targeted at the /cgi-bin/cstecgi.cgi URI. The request body is designed to invoke the setUPnPCfg function with specific parameters intended to toggle the state of the UPnP service.\nSince the function lacks secondary authorization logic, it blindly processes the parameters provided in the POST body and proceeds to apply the requested configuration change to the device's volatile or non-volatile memory.\nPayload Behavior: The payload involves sending a serialized request that instructs the setUPnPCfg routine to alter the UPnP daemon status. By manipulating these parameters, an attacker can force the device into a state where UPnP is enabled, effectively allowing internal services to map ports dynamically on the WAN interface.\nAuthentication and Privilege Requirements: This exploit requires zero authentication, meaning any attacker capable of reaching the device via the network can invoke this administrative function.\nPost-Exploitation Impact: Beyond the modification of UPnP settings, this vulnerability demonstrates a critical failure in the authentication architecture of the web-based management console. An attacker can leverage this unauthorized access to alter network behavior, potentially enabling port forwarding configurations that expose internal services (such as SSH, Telnet, or internal web interfaces) to the public internet, thereby significantly expanding the attack surface of the local area network."
}
CVE-2026-51677: TOTOLINK T6 UPnP Access Control (CRITICAL Severity, CVSS: 9.1) - Sceawere