CVE-2026-51705

TOTOLINK · T6

TOTOLINK T6 routers contain an incorrect access control vulnerability in the setWiFiMeshName function, allowing unauthenticated attackers to rename mesh entries via a crafted POST request.

Executive summary

An unauthenticated access control vulnerability in TOTOLINK T6 routers allows remote attackers to modify mesh configurations, posing a significant risk to device integrity.

Vulnerability

The flaw resides in the setWiFiMeshName function, where insufficient access control checks allow unauthenticated remote attackers to execute unauthorized configuration changes via the /cgi-bin/cstecgi.cgi endpoint.

Business impact

Successful exploitation of this vulnerability allows unauthorized modification of router mesh settings, which can lead to network disruption, man-in-the-middle attacks, or complete loss of control over the wireless environment. Given the high CVSS score of 9.8, this vulnerability represents a critical risk to organizational connectivity and internal network security, requiring immediate attention to prevent potential service downtime or unauthorized access.

Remediation

Immediate Action: Consult the official TOTOLINK support portal for firmware updates addressing this flaw, as no specific patch version is currently confirmed in the provided data.

Proactive Monitoring: Review web server and administrative access logs for suspicious POST requests directed at /cgi-bin/cstecgi.cgi, particularly from untrusted or external IP addresses.

Compensating Controls: Restrict management access to the router interface to trusted internal IP addresses only, and utilize a network firewall to block unauthorized external traffic to the device administration ports.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability is classified as critical due to its unauthenticated nature and the potential for total impact on the affected device. Administrators should prioritize isolating affected TOTOLINK T6 units from public-facing network segments until a verified firmware update is applied to remediate the access control failure.

More TOTOLINK CVEs

Sources