CVE-2026-51676
moderateUnauthenticated Access Control Flaw in TOTOLINK T6 Router
CVE-2026-51676 is an incorrect access control issue (CWE-284) in the setAccessDeviceCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to the router's web API endpoint /cgi-bin/cstecgi.cgi without any login credentials, causing the device to accept and apply access-device configuration changes. As a result, an attacker can modify the router's access-device policies — the rules governing how connected devices are permitted to use the network — with the critical 9.1 CVSS score reflecting potentially high confidentiality and integrity impact. Only TOTOLINK T6 routers running the named firmware build are identified as affected in the available data. There is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS currently assigns it a 0.4% probability of exploitation within 30 days, so no exploitation has been confirmed.
What to do: Owners of TOTOLINK T6 routers should check their current firmware version on the admin interface and apply an updated firmware from TOTOLINK when one becomes available (no fixed version is specified in the current data). Until patching, disable remote/WAN-side management or restrict access to the router's web interface and the /cgi-bin/cstecgi.cgi endpoint to trusted networks only. Defenders managing fleets of TOTOLINK devices should watch for a vendor advisory confirming the fix and affected version range.
| TOTOLINK T6 router | firmware 4.1.5cu.748_B20211015 (other firmware versions are not confirmed in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.