CVE-2026-51723: TOTOLINK T6 vulnerability
Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK T6to a version that resolves this vulnerability.Fixed in 4.1.5cu.748_B20211015 - Compensating control
Block unauthenticated access to /cgi-bin/cstecgi.cgi at the network layer (e.g., firewall/ACL) to prevent installation of custom CGI modules via crafted POST requests.
Event History
Frequently Asked Questions
Who is exposed to exploitation?
TOTOLINK T6 devices running firmware version 4.1.5cu.748_B20211015 are identified as affected. An attacker can target the device without authentication.
What does an attacker need to exploit this issue?
The attacker needs network access to the device's web management interface and must send a crafted POST request to /cgi-bin/cstecgi.cgi. No valid account credentials are required.
What is the likely impact of successful exploitation?
A successful attacker can install a custom CGI module on the affected device. This could allow unauthorized modification of web-accessible functionality on the router.