CVE-2026-51708

TOTOLINK · T6

An improper access control flaw in the TOTOLINK T6 router allows unauthenticated remote attackers to modify WPS settings via a crafted POST request to the administrative CGI interface.

Executive summary

A critical security vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to modify device configurations, posing a significant risk to network security.

Vulnerability

The device fails to perform adequate authorization checks within the setWiFiWpsCfg function. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to alter wireless configuration settings.

Business impact

Successful exploitation allows unauthorized modification of router settings, which can lead to the disabling of security features or the establishment of unauthorized network access. With a CVSS score of 9.8, this vulnerability is classified as critical due to the lack of required authentication and the potential for full configuration compromise. This exposure could facilitate further network infiltration or service disruption, resulting in severe operational and security consequences.

Remediation

Immediate Action: Consult the official TOTOLINK support portal to determine if a firmware update addressing this specific configuration vulnerability is available for the T6 model.

Proactive Monitoring: Review device access logs for suspicious POST requests targeting /cgi-bin/cstecgi.cgi, particularly from external or untrusted network interfaces.

Compensating Controls: Ensure the router management interface is not exposed to the public internet and restrict access to administrative functions to a dedicated, secure management VLAN or local network segment.

Exploitation status

Public Exploit Available: No (As of Aug 30, 2026, there is no confirmed public exploit or weaponized code available).

Analyst recommendation

Given the critical severity of this vulnerability and the ease with which an unauthenticated attacker can interact with the affected function, immediate action is required. Organizations utilizing the TOTOLINK T6 should prioritize restricting network access to the device management interface until a verified firmware patch is applied to remediate the underlying access control failure.

More TOTOLINK CVEs

Sources