CVE-2026-51684

TOTOLINK · T6

An unauthenticated access control vulnerability in the TOTOLINK T6 router allows attackers to modify storage service configurations via crafted POST requests to the cgi-bin interface.

Executive summary

A critical vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to modify device storage configurations, posing a significant risk of unauthorized service disruption or data manipulation.

Vulnerability

This vulnerability involves incorrect access control within the setStorageCfg function. An unauthenticated attacker can exploit this flaw by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to alter the state of storage-related services.

Business impact

The vulnerability carries a CVSS score of 9.8, indicating a critical severity level due to its potential for full system impact and ease of remote exploitation. Successful exploitation could allow an attacker to disrupt critical storage services, potentially leading to data loss, unauthorized access to sensitive files, or complete denial of service for the device.

Remediation

Immediate Action: Since a specific patch version is not currently identified, users should restrict access to the device management interface to trusted internal networks only. If the device is exposed to the public internet, disable remote management features immediately.

Proactive Monitoring: Monitor network traffic for suspicious POST requests directed at /cgi-bin/cstecgi.cgi and inspect system logs for unauthorized changes to storage configurations.

Compensating Controls: Deploy a Web Application Firewall (WAF) or equivalent network filter to block unauthorized POST requests targeting the identified CGI endpoint.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity and the lack of authentication required for exploitation, this vulnerability poses an immediate risk to the availability and integrity of TOTOLINK T6 devices. Administrators must prioritize isolating these devices from external networks and monitoring for any anomalous configuration changes until an official firmware update addressing the setStorageCfg access control flaw is released by the vendor.

More TOTOLINK CVEs all →

Sources