CVE-2026-51674

TOTOLINK · T6

An access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to trigger forced reboots by sending a crafted POST request to the cgi-bin interface.

Executive summary

An unauthenticated access control vulnerability in TOTOLINK T6 routers poses a critical risk by allowing remote attackers to disrupt device availability through unauthorized system reboots.

Vulnerability

This vulnerability is caused by improper access control in the setScheduleCfg function, which fails to verify the identity of the requester. Unauthenticated attackers can exploit this by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to manipulate scheduling configurations.

Business impact

The ability for an unauthenticated attacker to force a device reboot creates a significant risk of denial of service, which can disrupt business operations and network connectivity. Given the CVSS score of 9.8, this vulnerability is classified as critical because it allows remote, unauthenticated actors to exert full control over the power state of the affected hardware.

Remediation

Immediate Action: Contact the vendor or check the official TOTOLINK support portal for available firmware updates that address this access control flaw. If no update is available, restrict access to the device management interface to trusted internal networks only.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and keep logs of unexpected device reboots or configuration changes.

Compensating Controls: Implement firewall rules to block public access to the device administration interface and ensure that management functions are not exposed to the internet.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Due to the critical severity and the ease of exploitation, organizations should prioritize isolating affected TOTOLINK T6 devices from public-facing network segments. Security teams must verify the firmware version and apply vendor-provided patches as soon as they become available to eliminate the risk of unauthorized remote reboots.

More TOTOLINK CVEs

Sources