CVE-2026-51686
TOTOLINK · T6
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to reconfigure or disable wireless networks via a crafted POST request.
Executive summary
A critical access control vulnerability in the TOTOLINK T6 router permits unauthenticated remote attackers to modify wireless settings, potentially leading to a complete denial of service or network compromise.
Vulnerability
This vulnerability resides in the setWiFiEasyCfg function, which fails to perform necessary authentication checks. Unauthenticated attackers can exploit this by sending a malicious POST request to the /cgi-bin/cstecgi.cgi endpoint to alter router wireless configurations.
Business impact
The ability for an unauthenticated actor to reconfigure wireless settings poses a significant risk to organizational availability and security. With a CVSS score of 9.8, the vulnerability allows for total impact on confidentiality, integrity, and availability, potentially enabling attackers to disconnect legitimate users, redirect traffic, or disable security protocols.
Remediation
Immediate Action: Consult the vendor advisory and check the TOTOLINK support portal for firmware updates addressing this vulnerability. If no patch is currently available, restrict access to the management interface to trusted internal networks only.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and observe any unexpected changes to wireless network settings or SSID configurations.
Compensating Controls: Implement firewall rules to block external access to the device management interface, ensuring it is not exposed to the public internet.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity and the potential for total loss of network control, organizations using the TOTOLINK T6 must prioritize the identification and isolation of these devices. Administrators should ensure that management interfaces are not internet-facing and apply all vendor-supplied firmware updates as soon as they are made available to mitigate this high-risk vector.