CVE-2026-51668

TOTOLINK · T6

An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to modify language configurations via a crafted POST request.

Executive summary

A high-severity access control vulnerability in TOTOLINK T6 routers allows unauthenticated attackers to modify system configurations, posing a significant risk to device integrity.

Vulnerability

This vulnerability resides in the setLanguageCfg function, which fails to perform necessary authentication checks. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to alter the device language settings.

Business impact

Successful exploitation allows unauthorized configuration changes, which may serve as a precursor to more severe attacks or facilitate social engineering by manipulating the user interface language. With a CVSS score of 7.5, this high-severity flaw requires immediate attention to prevent unauthorized modification of network hardware, which could lead to broader network compromise or service disruption.

Remediation

Immediate Action: Consult the official TOTOLINK support portal for firmware updates addressing this vulnerability, as no specific patch version is currently confirmed.

Proactive Monitoring: Monitor device logs for unusual POST requests directed at /cgi-bin/cstecgi.cgi, specifically those originating from external or untrusted network segments.

Compensating Controls: Restrict administrative access to the device management interface to trusted internal IP addresses and employ a firewall to block unauthorized access to the web management console.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS rating and the ease of exploitation, organizations utilizing TOTOLINK T6 devices must prioritize securing the management interface. Administrators should restrict access to the web interface immediately and monitor vendor communications for a firmware patch to permanently resolve this access control failure.

More TOTOLINK CVEs all →

Sources