CVE-2026-51709
TOTOLINK · T6
An incorrect access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to reconfigure Wi-Fi settings via a crafted POST request.
Executive summary
A critical authentication bypass vulnerability in the TOTOLINK T6 router permits unauthenticated attackers to modify sensitive Wi-Fi configurations, posing a high risk of network compromise.
Vulnerability
The vulnerability exists within the setWiFiBasicCfg function, which fails to perform necessary authentication checks. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to alter primary wireless network settings.
Business impact
The ability for an unauthenticated attacker to reconfigure Wi-Fi settings allows for unauthorized network access, potential man-in-the-middle attacks, and total control over the wireless gateway. Given the CVSS score of 9.8, this vulnerability represents a critical risk that could lead to the complete compromise of data traversing the local network and unauthorized access to internal resources.
Remediation
Immediate Action: Consult the official TOTOLINK support portal to determine if a firmware update addressing this specific flaw has been released for the T6 model.
Proactive Monitoring: Review device logs for unusual POST requests directed toward /cgi-bin/cstecgi.cgi and monitor for unexpected changes in Wi-Fi configuration settings.
Compensating Controls: If a patch is unavailable, restrict access to the device management interface to trusted internal IP addresses only and disable remote administration features until the vulnerability is addressed.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
This vulnerability is highly critical due to the lack of required authentication for administrative actions. Organizations using the TOTOLINK T6 must prioritize the identification of a vendor-supplied firmware update. Until a patch is applied, ensure that management interfaces are not exposed to the public internet to mitigate the risk of unauthorized configuration changes.