CVE-2026-51713

TOTOLINK · T6

An improper access control flaw in TOTOLINK T6 allows unauthenticated attackers to manipulate WAN dial settings via crafted POST requests to the device.

Executive summary

A critical access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to modify WAN dial configurations, posing a significant risk to network integrity.

Vulnerability

This vulnerability resides in the setManualDialCfg function, which fails to perform necessary authentication checks. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to alter dial state settings.

Business impact

The vulnerability carries a CVSS score of 9.1, reflecting its critical nature and ease of exploitation. Successful manipulation of WAN dial settings can lead to unauthorized network redirection, denial of service for internet connectivity, or potential man-in-the-middle attacks, resulting in significant operational downtime and compromise of network traffic integrity.

Remediation

Immediate Action: Organizations using the affected TOTOLINK T6 device should restrict access to the web management interface to trusted internal networks only. If a firmware update is released by the vendor, it should be applied immediately.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and investigate any unauthorized changes to WAN configuration settings.

Compensating Controls: Implement firewall rules to block external access to the device management interface, ensuring the interface is not exposed to the public internet.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity of this vulnerability and the potential for total loss of control over WAN dial configurations, administrators must prioritize securing the device management interface. Exposure of the administration panel to the public internet should be eliminated immediately to prevent unauthorized access while awaiting further vendor guidance or firmware patches.

More TOTOLINK CVEs

Sources