ZeroHour

CVE-2026-51686

moderate

Unauthenticated access control flaw lets attackers alter TOTOLINK T6 Wi-Fi settings

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51686 is an incorrect access control flaw (CWE-284) in the setWiFiEasyCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, requiring no credentials or user interaction and exploitable over the network wherever the management interface is reachable, including from the internet if WAN-side management is enabled. A successful attack lets the attacker reconfigure or completely disable the device's wireless networks, disrupting connectivity for every client that depends on the router. Users and small organizations running a TOTOLINK T6 on the named firmware are affected; other firmware builds or models sharing the same CGI handler are not confirmed in this disclosure and should be verified with the vendor. The flaw is not currently known to be exploited: there is no public proof-of-concept, it is not in CISA KEV, and EPSS assigns it only a 0.4% probability of exploitation in the next 30 days (37th percentile), despite a critical CVSS 3.1 score of 9.8.

What to do: Restrict access to the router's /cgi-bin/cstecgi.cgi management endpoint by disabling WAN-side management or limiting it to trusted LAN clients, and monitor for unauthenticated POST requests invoking setWiFiEasyCfg. Because no fixed version is specified in the disclosure, check TOTOLINK's support/downloads page for updated T6 firmware and ask the vendor whether other firmware versions or models use the same affected handler.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (only firmware version named in the disclosure; other builds unconfirmed)
Estimated exposure
moderatelikely on the order of tens of thousands of T6 devices in use, of which several thousand are internet-exposed (estimate) — No official install counts exist for the T6; the estimate relies on TOTOLINK's consumer-router distribution footprint and public internet-exposure scans showing TOTOLINK devices numbering in the tens of thousands across all models, with a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.