CVE-2026-51677

TOTOLINK · T6

TOTOLINK T6 routers contain an incorrect access control vulnerability in the setUPnPCfg function, allowing unauthenticated attackers to modify UPnP settings via crafted POST requests.

Executive summary

An unauthenticated access control vulnerability in TOTOLINK T6 firmware allows remote attackers to manipulate UPnP service states, posing a critical security risk to network integrity.

Vulnerability

The vulnerability resides in the setUPnPCfg function, which fails to verify user credentials. An unauthenticated attacker can exploit this by sending a crafted HTTP POST request to the /cgi-bin/cstecgi.cgi endpoint to alter UPnP configurations.

Business impact

Successful exploitation of this flaw allows attackers to modify network device settings without authorization. Given the CVSS score of 9.1, this is classified as critical, as it could facilitate unauthorized traffic redirection or the opening of network ports, potentially leading to broader compromise of the internal network and significant security policy violations.

Remediation

Immediate Action: Consult the official TOTOLINK support portal to determine if a firmware update is available for your specific T6 hardware revision and apply it immediately.

Proactive Monitoring: Monitor network traffic for anomalous HTTP POST requests directed at /cgi-bin/cstecgi.cgi and inspect logs for unauthorized changes to UPnP service configurations.

Compensating Controls: Disable UPnP functionality on the device if it is not explicitly required for network operations, and restrict access to the device management interface to trusted internal IP addresses using firewall rules.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a critical risk to network security due to the lack of required authentication for configuration changes. Administrators are strongly advised to verify their firmware version and apply any available security patches provided by TOTOLINK. If no patch is available, disabling the vulnerable UPnP feature is the most effective method to neutralize this attack vector.

More TOTOLINK CVEs all →

Sources