CVE-2026-51710

TOTOLINK · T6

TOTOLINK T6 routers contain an incorrect access control vulnerability in the setParentalRules function, allowing unauthenticated attackers to modify parental controls via crafted POST requests.

Executive summary

An unauthenticated access control vulnerability in TOTOLINK T6 routers allows remote attackers to manipulate parental control settings, posing a significant risk to network security.

Vulnerability

This vulnerability involves incorrect access control within the setParentalRules function. Unauthenticated attackers can trigger this flaw by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint.

Business impact

The ability for an unauthenticated attacker to alter parental control configurations allows for the bypass of established internet safety and usage policies. Given the CVSS score of 9.1, this represents a critical risk, as it facilitates unauthorized control over network traffic management and potentially exposes connected users to restricted or harmful content.

Remediation

Immediate Action: Check the official TOTOLINK support portal for firmware updates addressing this flaw and apply them immediately if available.

Proactive Monitoring: Monitor network traffic for suspicious POST requests directed at the /cgi-bin/cstecgi.cgi interface, particularly those originating from untrusted external sources.

Compensating Controls: Restrict access to the router administrative interface to trusted internal IP addresses only, and ensure the device is not exposed directly to the public internet via WAN-side management.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical severity of this vulnerability, administrators should prioritize securing affected TOTOLINK T6 devices by isolating them from external network access. Verify firmware versions against the manufacturer guidance and apply patches as soon as they are released to prevent unauthorized manipulation of router security settings.

More TOTOLINK CVEs

Sources