CVE-2026-51692

TOTOLINK · T6

An unauthenticated access control vulnerability in the TOTOLINK T6 router allows attackers to modify guest wireless network configurations via a crafted POST request.

Executive summary

A critical access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to manipulate guest network settings, posing a significant risk to local network security.

Vulnerability

This vulnerability involves incorrect access control within the setWiFiGuestCfg function, which can be triggered by unauthenticated remote attackers sending malicious POST requests to the /cgi-bin/cstecgi.cgi endpoint.

Business impact

The ability for an unauthenticated attacker to alter guest wireless configurations presents a high risk of unauthorized network access and potential traffic interception. With a CVSS score of 9.1, this flaw is categorized as critical because it allows remote, unauthenticated exploitation that could lead to the compromise of network integrity and confidentiality for connected users.

Remediation

Immediate Action: Review the official TOTOLINK support portal for firmware updates addressing this flaw, as no specific patch version is currently identified.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed to the /cgi-bin/cstecgi.cgi endpoint and audit guest wireless network logs for unauthorized configuration changes.

Compensating Controls: Implement strict network segmentation and restrict access to the web management interface of the router to trusted internal IP addresses only.

Exploitation status

Public Exploit Available: No (There is no confirmed public exploit in the available data).

Analyst recommendation

Given the critical CVSS severity and the unauthenticated nature of the attack vector, administrators must prioritize the security of their TOTOLINK T6 devices. If a firmware update is not yet available, immediately isolate the device from public internet access to prevent exploitation. Monitor vendor communications closely for the release of a stable patch.

More TOTOLINK CVEs all →

Sources