CVE-2026-51691
TOTOLINK · T6
TOTOLINK T6 routers contain an incorrect access control vulnerability in the setUploadSetting function that allows unauthenticated attackers to manipulate system workflows via crafted POST requests.
Executive summary
A critical access control vulnerability in TOTOLINK T6 routers allows unauthenticated remote attackers to achieve full control over the device upload or flash workflow.
Vulnerability
The flaw exists in the setUploadSetting function, which fails to enforce authentication checks. An unauthenticated attacker can execute unauthorized actions by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint.
Business impact
The vulnerability carries a CVSS score of 9.8, indicating a critical severity level due to the potential for total system compromise. Successful exploitation allows an attacker to manipulate the firmware or configuration upload process, which could result in the installation of malicious firmware, persistent backdoors, or complete denial of service for the device.
Remediation
Immediate Action: Consult the official TOTOLINK support portal to determine if a firmware patch is available for the T6 model and apply it immediately. If no patch is available, isolate the device from the public internet to prevent remote access.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and review router logs for unauthorized configuration changes.
Compensating Controls: Implement strict firewall rules to restrict access to the management interface of the router, ensuring it is only accessible from trusted internal management subnets.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical CVSS score and the nature of the vulnerability, organizations must treat this as a high-priority security issue. If firmware updates are not provided by the vendor, the affected hardware should be replaced or permanently removed from network environments where it is exposed to untrusted traffic.