CVE-2026-51684
Received Received - Intake

Incorrect Access Control in TOTOLINK T6 Router

Vulnerability report for CVE-2026-51684, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: MITRE

Description

Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
totolink t6 4.1.5cu.748_b20211015

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an incorrect access control issue in the setStorageCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. It allows unauthenticated attackers to change storage-related service states by sending a specially crafted POST request to the vulnerable endpoint /cgi-bin/cstecgi.cgi.

Detection Guidance

To detect this vulnerability, monitor network traffic for POST requests to /cgi-bin/cstecgi.cgi with parameters targeting the setStorageCfg function. Check logs for unauthenticated access attempts to storage-related services.

Impact Analysis

An attacker could exploit this to alter storage services, potentially disrupting device functionality or causing data loss. Since no authentication is required, any network-accessible device with this firmware is at risk of unauthorized manipulation.

Mitigation Strategies

Immediately update the TOTOLINK T6 firmware to the latest version. Block external access to /cgi-bin/cstecgi.cgi via firewall rules. Disable unnecessary storage-related services if not in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-51684. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart