CVE-2026-51689

TOTOLINK · T6

An incorrect access control vulnerability in the TOTOLINK T6 firmware allows unauthenticated attackers to modify firmware upgrade workflows via crafted POST requests.

Executive summary

A critical access control flaw in TOTOLINK T6 routers allows unauthenticated remote attackers to manipulate firmware upgrade processes, potentially leading to unauthorized system changes.

Vulnerability

This vulnerability resides in the setUpgradeFW function, accessible via the /cgi-bin/cstecgi.cgi endpoint, and permits unauthenticated users to influence the device firmware upgrade workflow.

Business impact

The ability for an unauthenticated attacker to manipulate firmware upgrade processes presents a severe risk to network integrity and device security. With a CVSS score of 9.1, this vulnerability allows for unauthorized modifications that could lead to persistent device compromise, installation of malicious firmware, or complete denial of service, potentially impacting all downstream network traffic.

Remediation

Immediate Action: Consult the official TOTOLINK support portal for available firmware updates or security patches for the T6 model and apply them immediately.

Proactive Monitoring: Review device access logs for suspicious POST requests directed at /cgi-bin/cstecgi.cgi, particularly those originating from untrusted or external IP addresses.

Compensating Controls: Implement strict firewall rules to restrict management interface access to authorized internal IP addresses only, effectively isolating the device from the public internet.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical CVSS severity and the ease of exploitation over the network, organizations utilizing the TOTOLINK T6 must prioritize this issue. If a firmware update is not currently available, administrators should immediately restrict network access to the device management interface to prevent exploitation by external actors.

More TOTOLINK CVEs all →

Sources