CVE-2026-51717

TOTOLINK · T6

An access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to modify the device operating mode via a crafted POST request to the cgi-bin interface.

Executive summary

A critical access control flaw in TOTOLINK T6 routers allows unauthenticated remote attackers to modify device configurations, potentially leading to a full loss of network integrity.

Vulnerability

The vulnerability exists within the setOpModeCfg function, which fails to perform necessary authentication checks. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to alter system operating modes.

Business impact

This vulnerability carries a CVSS score of 9.1, indicating a critical risk to business operations. By unauthorized modification of device operating modes, an attacker could redirect traffic, intercept sensitive data, or render the router inoperable, leading to significant service disruption and potential compromise of internal network security.

Remediation

Immediate Action: Check the official TOTOLINK support portal for firmware updates addressing this flaw and apply them to all affected T6 units immediately. If no patch is currently available for your specific build, restrict access to the web management interface to trusted internal networks only.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and review administrative logs for unauthorized changes to device configurations.

Compensating Controls: Implement firewall rules to block external access to the device management interface, ensuring it is only reachable from a secure, isolated management VLAN or via VPN.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical nature of this access control bypass and the potential for complete device manipulation, organizations must treat this vulnerability with high priority. Administrators should audit their device inventory for the affected firmware version and restrict management interface access until a confirmed vendor patch is applied.

More TOTOLINK CVEs

Sources