Sceawere

Vulnerability Detail

CVE-2026-51742UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Unauthenticated WAN Discovery

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
9h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-09-01T13:19:45.160Z",
  "pubdate": "2026-09-01T13:19:45.160Z",
  "executiveSummary": "This vulnerability concerns an improper access control flaw within the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015.\nThe issue manifests in the discoverWan function, which is exposed via the /cgi-bin/cstecgi.cgi interface, failing to enforce necessary authentication checks.\nThis security weakness allows unauthenticated, remote attackers to trigger the WAN discovery logic without valid credentials.\nSuccessful exploitation facilitates unauthorized interactions with the device's network configuration processes, which could be leveraged to disrupt connectivity or facilitate further network-level reconnaissance.\nThe vulnerability represents a significant risk to device integrity as it bypasses standard access control mechanisms, granting an unauthenticated entity the ability to influence sensitive system functions.\nExposure of this function across network interfaces increases the attack surface, allowing remote exploitation by any entity capable of reaching the CGI endpoint.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient authorization logic implemented in the discoverWan function of the TOTOLINK T6 firmware (4.1.5cu.748_B20211015).\nThe web management interface utilizes /cgi-bin/cstecgi.cgi as a primary gateway for administrative commands. Analysis reveals that the backend handling of requests for the discoverWan routine lacks mandatory session validation or cryptographic token verification for the specific HTTP POST requests routed to this endpoint.\nThe exploitation flow begins when an attacker crafts a specifically formatted HTTP POST request directed at the /cgi-bin/cstecgi.cgi path. Because the underlying logic fails to verify the requestor's identity, the application passes the request parameters to the vulnerable discoverWan function without restriction.\nUpon receiving the malicious request, the device executes the WAN discovery logic, which typically involves scanning or renegotiating wide area network interfaces. By manipulating the parameters sent during this request, an attacker may force the device to restart WAN discovery processes, potentially leading to a denial-of-service condition or the exposure of network topology information.\nThe lack of authentication requirements allows this attack to be performed entirely remotely over the network. Since there is no requirement for valid session cookies or administrative credentials, the barrier to exploitation is minimal, requiring only knowledge of the specific CGI interface and the parameters expected by the discoverWan function.\nThe post-exploitation impact includes unauthorized state transitions of the WAN interface. By forcing unexpected discovery cycles, an attacker can induce instability in the device's internet connectivity or utilize the response from the discovery mechanism to fingerprint upstream network configurations. This highlights a failure in the Principle of Least Privilege, as a management function that modifies system state is exposed to the unauthenticated public-facing portion of the web server."
}
CVE-2026-51742: TOTOLINK T6 Unauthenticated WAN Discovery (MEDIUM Severity, CVSS: 5.9) - Sceawere