CVE-2026-51668
TOTOLINK · T6
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to modify language configurations via a crafted POST request.
Executive summary
A high-severity access control vulnerability in TOTOLINK T6 routers allows unauthenticated attackers to modify system configurations, posing a significant risk to device integrity.
Vulnerability
This vulnerability resides in the setLanguageCfg function, which fails to perform necessary authentication checks. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to alter the device language settings.
Business impact
Successful exploitation allows unauthorized configuration changes, which may serve as a precursor to more severe attacks or facilitate social engineering by manipulating the user interface language. With a CVSS score of 7.5, this high-severity flaw requires immediate attention to prevent unauthorized modification of network hardware, which could lead to broader network compromise or service disruption.
Remediation
Immediate Action: Consult the official TOTOLINK support portal for firmware updates addressing this vulnerability, as no specific patch version is currently confirmed.
Proactive Monitoring: Monitor device logs for unusual POST requests directed at /cgi-bin/cstecgi.cgi, specifically those originating from external or untrusted network segments.
Compensating Controls: Restrict administrative access to the device management interface to trusted internal IP addresses and employ a firewall to block unauthorized access to the web management console.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS rating and the ease of exploitation, organizations utilizing TOTOLINK T6 devices must prioritize securing the management interface. Administrators should restrict access to the web interface immediately and monitor vendor communications for a firmware patch to permanently resolve this access control failure.