CVE-2026-51673

TOTOLINK · T6

TOTOLINK T6 routers contain an incorrect access control vulnerability in the setNtpCfg function, allowing unauthenticated attackers to modify time synchronization settings via crafted POST requests.

Executive summary

An unauthenticated access control vulnerability in TOTOLINK T6 routers allows remote attackers to manipulate critical device time settings, potentially facilitating further attacks.

Vulnerability

The device fails to properly restrict access to the setNtpCfg function within the /cgi-bin/cstecgi.cgi endpoint. This allows an unauthenticated attacker to inject malicious NTP configurations, which can be used to disrupt network operations or bypass time-dependent security controls.

Business impact

Successful exploitation of this vulnerability permits unauthorized modification of router settings, which poses a significant threat to network integrity. Given the CVSS score of 7.5, this high-severity flaw could lead to service disruption or facilitate man-in-the-middle attacks by misconfiguring time synchronization, potentially invalidating security certificates or logs.

Remediation

Immediate Action: Consult the official TOTOLINK support portal for available firmware updates addressing this flaw and apply them to all affected T6 units immediately.

Proactive Monitoring: Monitor device logs for anomalous POST requests directed at the /cgi-bin/cstecgi.cgi endpoint, specifically identifying traffic originating from unauthorized or external IP ranges.

Compensating Controls: Restrict access to the router administrative interface by ensuring it is not exposed to the public internet and by implementing strict firewall rules to limit management access to trusted internal IP addresses only.

Exploitation status

Public Exploit Available: No (no confirmation of a weaponized exploit or public proof-of-concept exists in available data).

Analyst recommendation

The risk associated with this vulnerability is elevated due to its remote, unauthenticated nature. Organizations utilizing TOTOLINK T6 hardware should prioritize isolating these devices from external network exposure until official firmware updates are confirmed, tested, and deployed across the environment.

More TOTOLINK CVEs all →

Sources