Sceawere

Vulnerability Detail

CVE-2026-51698UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Incorrect Access Control

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-31T16:18:34.927Z",
  "pubdate": "2026-08-31T16:18:34.927Z",
  "executiveSummary": "The TOTOLINK T6 router, specifically firmware version 4.1.5cu.748_B20211015, contains a critical vulnerability characterized by improper access control within its web management interface.\nThe vulnerability resides in the setUrlFilterRules function, which fails to adequately enforce authentication checks for administrative requests.\nThis flaw allows remote, unauthenticated attackers to modify critical browsing policy configurations by submitting a maliciously crafted POST request to the /cgi-bin/cstecgi.cgi endpoint.\nSuccessful exploitation grants an unauthorized user the ability to bypass security constraints, potentially leading to unauthorized network filtering modifications, content redirection, or arbitrary disruption of internet access for connected clients.\nThe vulnerability represents a significant security risk, as it permits low-complexity attacks that do not require prior knowledge of legitimate user credentials.\nGiven the nature of the affected device as a network gateway, the potential for unauthorized policy alteration poses a direct threat to the integrity and confidentiality of the internal network's traffic management.",
  "technicalDetails": "The root cause of this vulnerability is an insufficient authentication validation mechanism within the /cgi-bin/cstecgi.cgi script, which serves as the primary gateway for administrative actions on the TOTOLINK T6 device.\nSpecifically, the setUrlFilterRules function, responsible for processing URL filtering configurations, is improperly exposed without the requisite session validation or access control checks. Consequently, the application processes POST requests containing configuration parameters for URL filtering rules even when the request originates from an unauthenticated source.\nThe attack flow begins when an attacker sends an unauthenticated HTTP POST request to the /cgi-bin/cstecgi.cgi endpoint. The request payload is engineered to include parameters intended for the setUrlFilterRules function. Because the underlying CGI handler fails to verify the session state or the identity of the requester, the device processes the payload and updates the device's internal browsing policy database accordingly.\nThis behavior exposes the device to unauthorized administrative modification. An attacker could, for instance, configure arbitrary URL filters, thereby enabling the censorship of specific web traffic or the redirection of user requests to malicious endpoints controlled by the attacker. Since this configuration change occurs at the firmware level, the impact is persistent and directly affects the networking behavior of all connected clients.\nThe vulnerability is inherent to the logic of the setUrlFilterRules function and the associated web service handler, which lack robust input validation and identity assertion. By circumventing authentication, an attacker can manipulate the routing and filtering tables of the router with minimal interaction. This vulnerability highlights a failure in the secure implementation of administrative API endpoints, which should strictly require a validated, privileged session before permitting any modification of security-relevant configurations.\nPost-exploitation, the attacker maintains influence over the victim's web access patterns. The persistent nature of such policy changes means the impact continues until the affected settings are manually reset or overwritten by an authorized administrator. Given that the affected component is a gateway device, this vulnerability effectively grants an external actor control over the security posture of the local area network (LAN)."
}
CVE-2026-51698: TOTOLINK T6 Incorrect Access Control (CRITICAL Severity, CVSS: 9.1) - Sceawere