CVE-2026-51717
TOTOLINK · T6
An access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to modify the device operating mode via a crafted POST request to the cgi-bin interface.
Executive summary
A critical access control flaw in TOTOLINK T6 routers allows unauthenticated remote attackers to modify device configurations, potentially leading to a full loss of network integrity.
Vulnerability
The vulnerability exists within the setOpModeCfg function, which fails to perform necessary authentication checks. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to alter system operating modes.
Business impact
This vulnerability carries a CVSS score of 9.1, indicating a critical risk to business operations. By unauthorized modification of device operating modes, an attacker could redirect traffic, intercept sensitive data, or render the router inoperable, leading to significant service disruption and potential compromise of internal network security.
Remediation
Immediate Action: Check the official TOTOLINK support portal for firmware updates addressing this flaw and apply them to all affected T6 units immediately. If no patch is currently available for your specific build, restrict access to the web management interface to trusted internal networks only.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and review administrative logs for unauthorized changes to device configurations.
Compensating Controls: Implement firewall rules to block external access to the device management interface, ensuring it is only reachable from a secure, isolated management VLAN or via VPN.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical nature of this access control bypass and the potential for complete device manipulation, organizations must treat this vulnerability with high priority. Administrators should audit their device inventory for the affected firmware version and restrict management interface access until a confirmed vendor patch is applied.