Sceawere

Vulnerability Detail

CVE-2026-51693UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Incorrect Access Control

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-31T15:17:20.963Z",
  "pubdate": "2026-08-31T15:17:20.963Z",
  "executiveSummary": "A critical incorrect access control vulnerability has been identified in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015, specifically within the setVpnPassCfg function. This flaw allows unauthenticated remote attackers to manipulate VPN configuration parameters by dispatching maliciously crafted POST requests to the /cgi-bin/cstecgi.cgi endpoint.\nThe vulnerability stems from improper validation of authentication tokens or authorization checks within the device's web management interface. Successful exploitation facilitates the weakening of edge filtering mechanisms, potentially bypassing established security policies and exposing the internal network to unauthorized traffic or reconnaissance.\nThe risk level is significant, as the vulnerability does not require prior authentication or elevated privileges, making it accessible to any actor with network reach to the target device. Unauthorized modification of VPN settings could lead to complete loss of network integrity, interception of encrypted traffic, or persistent backdoors. Organizations utilizing this hardware should prioritize network segmentation and restrict access to the web management interface to mitigate exposure.",
  "technicalDetails": "The vulnerability resides in the setVpnPassCfg function, which is exposed via the /cgi-bin/cstecgi.cgi common gateway interface script on TOTOLINK T6 devices running firmware 4.1.5cu.748_B20211015. The core issue is a failure to enforce adequate session validation or access control lists (ACLs) before executing configuration changes related to VPN settings.\nExploitation is conducted through a crafted HTTP POST request directed at the cstecgi.cgi binary. The attacker leverages the interface to interact with internal API handlers responsible for managing VPN configuration states. Because the application logic fails to verify the existence of a valid administrative session cookie or token, the server processes the user-supplied data as a legitimate request from an authorized administrator.\nThe attack flow proceeds as follows: 1) The attacker identifies a network-accessible TOTOLINK T6 device. 2) The attacker constructs an HTTP POST request containing specific parameters targeted at the setVpnPassCfg function. 3) The request is transmitted to the /cgi-bin/cstecgi.cgi handler without accompanying valid authentication headers. 4) The server-side logic processes the POST body, effectively modifying the configuration state of the device’s VPN pass-through or firewall filtering rules.\nThe impact of this vulnerability is the deliberate weakening of edge filtering. By manipulating the parameters passed to the setVpnPassCfg function, an attacker can influence how the device handles inbound packets or protocol-specific traffic. This modification can effectively disable security controls, allowing traffic that would otherwise be blocked by the firewall to reach downstream resources. Post-exploitation, an attacker may leverage this access to establish unauthorized persistence or facilitate lateral movement within the network. The lack of cryptographic signing for configuration changes ensures that the device blindly accepts these illicit inputs, provided they conform to the expected format required by the CGI parser. The vulnerability highlights a systemic failure in the device's security model, where sensitive administrative functions are exposed to the public-facing network interface without secondary verification mechanisms."
}
CVE-2026-51693: TOTOLINK T6 Incorrect Access Control (CRITICAL Severity, CVSS: 9.8) - Sceawere