CVE-2026-51722
TOTOLINK · T6
An unauthenticated access control vulnerability in the TOTOLINK T6 router allows attackers to redirect device traffic to an upstream Wi-Fi network via a crafted POST request.
Executive summary
A critical vulnerability in TOTOLINK T6 routers allows unauthenticated attackers to hijack network traffic by manipulating device configuration settings.
Vulnerability
This is an improper access control vulnerability located in the setWiFiRepeaterCfg function. Unauthenticated attackers can exploit this flaw by sending a malicious POST request to the /cgi-bin/cstecgi.cgi endpoint to reconfigure the device upstream connection.
Business impact
Successful exploitation of this vulnerability allows an attacker to intercept or redirect network traffic, leading to significant risk of data theft, credential harvesting, and man-in-the-middle attacks. Given the CVSS score of 9.1, this flaw represents a critical threat to organizational network integrity that could facilitate widespread unauthorized access to internal communications.
Remediation
Immediate Action: Consult the official TOTOLINK support portal to determine if a firmware update addressing this specific configuration vulnerability is available for the T6 model.
Proactive Monitoring: Monitor network traffic logs for anomalous POST requests directed at /cgi-bin/cstecgi.cgi and investigate any unauthorized changes to Wi-Fi repeater or upstream network settings.
Compensating Controls: Restrict administrative access to the web management interface to trusted internal IP addresses only, and disable the Wi-Fi repeater functionality if it is not required for current business operations.
Exploitation status
Public Exploit Available: No (There is no confirmed public exploit available in the provided data).
Analyst recommendation
Due to the critical nature of this vulnerability and the existence of proof-of-concept material, administrators should prioritize securing affected TOTOLINK T6 devices immediately. If a patch is not currently provided by the vendor, implement strict network segmentation to isolate these devices from sensitive data environments until a secure configuration or update can be verified.