CVE-2026-51679

9.1

TOTOLINK · T6

An incorrect access control vulnerability in the TOTOLINK T6 setPasswordCfg function allows unauthenticated attackers to modify administrator account settings via a crafted POST request.

Executive summary

A critical access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to compromise administrative account security.

Vulnerability

The vulnerability exists within the setPasswordCfg function, which fails to perform necessary authentication checks. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the cgi-bin/cstecgi.cgi endpoint to alter administrative configurations.

Business impact

The ability for an unauthenticated attacker to modify administrative credentials poses a severe risk to network integrity and confidentiality. With a CVSS score of 9.1, this flaw could lead to a complete takeover of the router, allowing attackers to intercept traffic, redirect users to malicious sites, or gain persistent access to the local network. Such an incident would likely result in significant downtime and a total breach of trust regarding internal communications.

Remediation

Immediate Action: Users should visit the official TOTOLINK support website to check for and apply the latest available firmware updates. If an update is not yet available for this specific build, prioritize isolating the device from the public internet.

Proactive Monitoring: Monitor device logs for anomalous POST requests directed at cgi-bin/cstecgi.cgi and keep a close watch for unexpected changes to administrative account settings or configurations.

Compensating Controls: Implement strict firewall rules to restrict access to the device management interface, ensuring it is not reachable from untrusted networks or the public internet.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical severity score and the potential for total administrative takeover, immediate attention is required. Organizations using the TOTOLINK T6 device should restrict management access to trusted internal IP ranges and apply any security patches provided by the vendor as soon as they are released to neutralize this vector.

More TOTOLINK CVEs

Sources