Summary
CVE-2026-51684 is a critical improper access control vulnerability (CWE-284) in the setStorageCfg function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to alter the router’s storage-related service state by sending a crafted POST request to the device’s CGI endpoint. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: the
setStorageCfgfunction fails to enforce authentication/authorization checks before processing configuration requests. - Trigger condition: an attacker sends a crafted HTTP POST request to
/cgi-bin/cstecgi.cgitargeting thesetStorageCfgaction. - Attack vector: network-based, no authentication or user interaction required, low attack complexity.
- Impact: unauthorized attackers can modify storage-related service settings on the device, with the CVSS vector indicating high impact to confidentiality, integrity, and availability.
Affected software
- TOTOLINK T6, firmware version 4.1.5cu.748_B20211015
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No official TOTOLINK patch or advisory addressing this specific CVE has been identified at this time. Check TOTOLINK’s official site (totolink.net) for updated firmware for the T6 model and apply any available update that addresses this issue.
- If no patch is available: Restrict access to the router’s management/CGI interface (
/cgi-bin/cstecgi.cgi) to trusted internal networks only, disable remote/WAN administration, and place the device behind a firewall or VPN so it is not directly reachable from the internet.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/cgi-bin/cstecgi.cgi - Page title:
TOTOLINK

