CVE-2026-51687

TOTOLINK · T6

An incorrect access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to modify guest wireless settings via a crafted POST request to the cstecgi.cgi endpoint.

Executive summary

A critical vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to manipulate guest wireless access configurations, posing a significant risk to network security.

Vulnerability

The vulnerability exists within the setWiFiEasyGuestCf function, which fails to perform necessary authentication checks. An unauthenticated attacker can exploit this by sending a malicious POST request to the /cgi-bin/cstecgi.cgi endpoint to weaken or create unauthorized guest wireless access.

Business impact

The ability for an unauthenticated attacker to alter network configurations represents a severe security failure. With a CVSS score of 9.1, this flaw could allow unauthorized entities to bypass perimeter security, facilitate man-in-the-middle attacks, or provide a foothold for lateral movement within the corporate or home network.

Remediation

Immediate Action: Check the official TOTOLINK support portal for available firmware updates and apply them immediately if a patched version is released. If no patch is available, isolate the affected device from the public internet.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and review wireless access logs for unauthorized guest account creation.

Compensating Controls: If the device cannot be updated, ensure it is placed behind a robust firewall and disable remote management features to prevent external access to the vulnerable CGI interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability and its potential to compromise network integrity, organizations must treat this as a high-priority issue. Administrators should verify the current firmware version and prepare to apply the vendor update as soon as it is provided, while implementing strict network segmentation to limit the exposure of the affected device.

More TOTOLINK CVEs all →

Sources