Sceawere
Vulnerability Detail
CVE-2026-51681UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
TOTOLINK T6 Remote Access Control Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 18h ago
- Vendor
- n/a
- Product
- n/a
- Attack Type
- n/a
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-08-31T14:17:16.323Z",
"pubdate": "2026-08-31T14:17:16.323Z",
"executiveSummary": "This vulnerability involves an incorrect access control flaw within the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015, specifically residing in the setRemoteCfg function.\nThe vulnerability allows an unauthenticated, remote attacker to manipulate the device's configuration, effectively enabling administration access via the WAN interface.\nThis represents a critical security risk as it facilitates unauthorized modification of device settings, potentially leading to full device compromise or remote management exposure to the public internet.\nThe exploitation does not require prior authentication or elevated privileges, making it highly accessible to remote adversaries capable of reaching the device's management interface.\nThe impact includes the exposure of the administrative portal to the WAN, violating the security boundary intended to restrict management functions to the LAN, thereby increasing the attack surface significantly.",
"technicalDetails": "The vulnerability originates from a deficiency in access control logic within the setRemoteCfg function located within the firmware's backend processing logic, specifically triggered via requests handled by /cgi-bin/cstecgi.cgi.\nThe root cause is the failure of the application to verify the authentication status of the requester before executing configuration changes related to remote administration settings.\nThe exploitation flow begins when an attacker crafts a malicious HTTP POST request directed at the /cgi-bin/cstecgi.cgi endpoint. This request is designed to interact with the setRemoteCfg function, which is responsible for updating the device's remote management configuration parameters.\nBecause the function fails to perform a mandatory security check to validate session tokens or authentication cookies, the device processes the payload as a legitimate administrative request.\nBy manipulating specific parameters within the POST data, the attacker can force the device to toggle the status of the WAN-side administration service. Once enabled, the administrative interface, which should typically remain isolated to the internal network, becomes accessible via the device's WAN IP address.\nThis effectively circumvents the security policy intended to prevent external entities from attempting to authenticate against or probe the web management interface.\nOnce the WAN-side administration is exposed, the attacker can move to subsequent phases of an attack, such as credential brute-forcing or leveraging additional secondary vulnerabilities present in the management interface to achieve remote code execution (RCE) or complete administrative takeover of the device.\nThe vulnerability is inherent to the logic of the setRemoteCfg function and persists as long as the affected firmware version, 4.1.5cu.748_B20211015, is in operation."
}