Sceawere

Vulnerability Detail

CVE-2026-51739UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Incorrect Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-08-31T20:17:05.210Z",
  "pubdate": "2026-08-31T20:17:05.210Z",
  "executiveSummary": "The TOTOLINK T6 router (version 4.1.5cu.748_B20211015) contains an incorrect access control vulnerability within its firmware update mechanisms. This flaw resides in the CloudSrvVersionCheck function, which manages cloud-based firmware update verification requests. An unauthenticated remote attacker can exploit this vulnerability by sending a maliciously crafted POST request to the cgi-bin/cstecgi.cgi endpoint. The vulnerability allows unauthorized actors to trigger the device's cloud update check routine without valid administrative credentials. While the primary impact involves forcing unauthorized update checks, such flaws in router management interfaces often serve as entry points for more severe exploitation, including potential state manipulation or the triggering of secondary vulnerabilities within the update process. The lack of authentication requirements significantly lowers the barrier for exploitation, making the device susceptible to external manipulation from any network-adjacent attacker.",
  "technicalDetails": "The vulnerability is rooted in an improper authorization check within the CloudSrvVersionCheck function, which fails to validate the requestor's session or administrative status before initiating the cloud-based version verification procedure. The function is exposed via the /cgi-bin/cstecgi.cgi Common Gateway Interface (CGI) script, which serves as a central controller for various administrative and system management tasks on the TOTOLINK T6 device.\nThe attack vector involves the transmission of a crafted POST request directed at the /cgi-bin/cstecgi.cgi endpoint. Because the underlying CGI handler does not properly enforce authentication logic for the specific request parameters associated with the CloudSrvVersionCheck routine, the application logic proceeds to execute the function when invoked. This bypasses the intended security boundary that restricts administrative functions to authenticated users.\nThe technical flow of the exploit proceeds as follows: First, the attacker identifies the exposed endpoint /cgi-bin/cstecgi.cgi, which is accessible over standard network protocols. Second, the attacker crafts a POST request that triggers the CloudSrvVersionCheck logic. This is achieved by formatting the payload in a manner that the CGI parser interprets as a request to verify the firmware version against the manufacturer's cloud service. Third, the system processes this request without checking for a valid session token or authentication cookie. Fourth, the system initiates network activity to the hardcoded cloud update servers, effectively forcing the device to perform a check that should only be triggered by an authorized administrator.\nThis vulnerability is particularly concerning because the CGI handler lacks adequate request validation and access control mechanisms, which are fundamental for maintaining the security integrity of network infrastructure devices. The lack of authorization allows an attacker to interact with the device's update subsystems, which may contain further logic flaws or memory corruption vulnerabilities. By triggering these functions remotely, an attacker can influence the device's operational state. The exposure is not limited to local network access; depending on the device's configuration, the management interface may be reachable from the WAN interface, extending the threat surface to any remote actor capable of reaching the device via the internet."
}
CVE-2026-51739: TOTOLINK T6 Incorrect Access Control (MEDIUM Severity, CVSS: 5.9) - Sceawere