CVE-2026-51688
TOTOLINK · T6
An access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to trigger a denial of service or reduce wireless signal power via a crafted POST request.
Executive summary
A high severity access control flaw in the TOTOLINK T6 router allows unauthenticated remote attackers to disrupt wireless connectivity or cause a device denial of service.
Vulnerability
This vulnerability involves incorrect access control within the setWiFiSignalCfg function, which fails to validate incoming requests. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the cgi-bin/cstecgi.cgi endpoint to modify device settings or crash the service.
Business impact
The ability for an unauthenticated attacker to manipulate wireless power levels or force a denial of service poses a significant risk to network availability. With a CVSS score of 7.5, this vulnerability is classified as high severity, as it allows for the remote disruption of critical business communications without requiring valid user credentials.
Remediation
Immediate Action: Review the official TOTOLINK support portal for available firmware updates and apply them to the affected T6 devices immediately.
Proactive Monitoring: Monitor network traffic logs for anomalous POST requests directed at the cgi-bin/cstecgi.cgi endpoint, which may indicate attempted exploitation.
Compensating Controls: Restrict management interface access to trusted internal IP addresses using firewall rules to prevent unauthorized access from external or untrusted networks.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the ease of exploitability and the potential for complete loss of wireless service, administrators should prioritize patching these devices. If a firmware update is not yet available for your specific regional hardware revision, implementing network-level access controls to isolate the management interface is essential to mitigate the risk of remote attack.