CVE-2026-51688

TOTOLINK · T6

An access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to trigger a denial of service or reduce wireless signal power via a crafted POST request.

Executive summary

A high severity access control flaw in the TOTOLINK T6 router allows unauthenticated remote attackers to disrupt wireless connectivity or cause a device denial of service.

Vulnerability

This vulnerability involves incorrect access control within the setWiFiSignalCfg function, which fails to validate incoming requests. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the cgi-bin/cstecgi.cgi endpoint to modify device settings or crash the service.

Business impact

The ability for an unauthenticated attacker to manipulate wireless power levels or force a denial of service poses a significant risk to network availability. With a CVSS score of 7.5, this vulnerability is classified as high severity, as it allows for the remote disruption of critical business communications without requiring valid user credentials.

Remediation

Immediate Action: Review the official TOTOLINK support portal for available firmware updates and apply them to the affected T6 devices immediately.

Proactive Monitoring: Monitor network traffic logs for anomalous POST requests directed at the cgi-bin/cstecgi.cgi endpoint, which may indicate attempted exploitation.

Compensating Controls: Restrict management interface access to trusted internal IP addresses using firewall rules to prevent unauthorized access from external or untrusted networks.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the ease of exploitability and the potential for complete loss of wireless service, administrators should prioritize patching these devices. If a firmware update is not yet available for your specific regional hardware revision, implementing network-level access controls to isolate the management interface is essential to mitigate the risk of remote attack.

More TOTOLINK CVEs all →

Sources