CVE-2026-51728

TOTOLINK · T6

An incorrect access control vulnerability in the UploadFirmwareFile function of the TOTOLINK T6 router allows unauthenticated remote attackers to upload arbitrary firmware images.

Executive summary

A critical authentication bypass in TOTOLINK T6 routers enables unauthenticated attackers to achieve full system compromise via malicious firmware uploads.

Vulnerability

The device lacks proper access control on the UploadFirmwareFile function, which is accessible via the /cgi-bin/cstecgi.cgi endpoint. This allows any unauthenticated attacker to send a specially crafted POST request to overwrite device firmware.

Business impact

The ability to upload arbitrary firmware carries a CVSS score of 9.8, indicating the highest level of severity. Successful exploitation allows for complete remote control of the device, which could lead to persistent backdoors, total data interception, and the potential to use the compromised hardware as a pivot point for lateral movement within the internal network.

Remediation

Immediate Action: Disconnect affected TOTOLINK T6 devices from the public internet immediately and restrict administrative access to trusted management subnets until a vendor firmware patch is confirmed and applied.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and inspect device logs for unauthorized administrative access or firmware update attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an intrusion prevention system to block unauthorized traffic destined for the /cgi-bin/cstecgi.cgi endpoint.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical nature of this vulnerability and the potential for total device takeover, immediate isolation of the affected hardware is required. Administrators should prioritize disabling remote management features and verify the integrity of device firmware. Monitor the official TOTOLINK support portal for the release of a security patch and apply it as soon as it becomes available.

More TOTOLINK CVEs

Sources