CVE-2026-51734

TOTOLINK · T6

An incorrect access control flaw in the TOTOLINK T6 router allows unauthenticated attackers to trigger mesh slave update processes via a crafted POST request to the cstecgi.cgi endpoint.

Executive summary

A critical access control vulnerability in the TOTOLINK T6 router permits unauthenticated remote attackers to trigger unauthorized mesh slave update coordination, potentially leading to full system compromise.

Vulnerability

This vulnerability resides in the informSlaveUpdate function, which fails to perform necessary authentication checks. An unauthenticated attacker can send a malicious POST request to the /cgi-bin/cstecgi.cgi endpoint to execute unauthorized administrative functions.

Business impact

The CVSS score of 9.8 reflects the high risk posed by this vulnerability, as it allows complete compromise of the device without any user interaction or authentication. Successful exploitation could lead to unauthorized control over network infrastructure, potentially facilitating further attacks on internal systems, data interception, or complete denial of service for connected users.

Remediation

Immediate Action: Review the official TOTOLINK support portal for firmware updates addressing this flaw, or contact the vendor directly if no patch is listed for your specific hardware revision.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and review device logs for unauthorized administrative activity or unexpected mesh update operations.

Compensating Controls: Deploy a network firewall to restrict access to the device management interface, ensuring it is not exposed to the public internet.

Exploitation status

Public Exploit Available: No (exploit_available is false/unknown).

Analyst recommendation

Given the critical severity of this vulnerability, administrators should prioritize restricting access to the affected TOTOLINK T6 management interface immediately. Until a verified vendor patch is applied, ensure the device is isolated from external network access to prevent potential exploitation by remote attackers.

More TOTOLINK CVEs

Sources