CVE-2026-51686

TOTOLINK · T6

An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to reconfigure or disable wireless networks via a crafted POST request.

Executive summary

A critical access control vulnerability in the TOTOLINK T6 router permits unauthenticated remote attackers to modify wireless settings, potentially leading to a complete denial of service or network compromise.

Vulnerability

This vulnerability resides in the setWiFiEasyCfg function, which fails to perform necessary authentication checks. Unauthenticated attackers can exploit this by sending a malicious POST request to the /cgi-bin/cstecgi.cgi endpoint to alter router wireless configurations.

Business impact

The ability for an unauthenticated actor to reconfigure wireless settings poses a significant risk to organizational availability and security. With a CVSS score of 9.8, the vulnerability allows for total impact on confidentiality, integrity, and availability, potentially enabling attackers to disconnect legitimate users, redirect traffic, or disable security protocols.

Remediation

Immediate Action: Consult the vendor advisory and check the TOTOLINK support portal for firmware updates addressing this vulnerability. If no patch is currently available, restrict access to the management interface to trusted internal networks only.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and observe any unexpected changes to wireless network settings or SSID configurations.

Compensating Controls: Implement firewall rules to block external access to the device management interface, ensuring it is not exposed to the public internet.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity and the potential for total loss of network control, organizations using the TOTOLINK T6 must prioritize the identification and isolation of these devices. Administrators should ensure that management interfaces are not internet-facing and apply all vendor-supplied firmware updates as soon as they are made available to mitigate this high-risk vector.

More TOTOLINK CVEs all →

Sources