CVE-2026-51687
largeUnauthenticated access control flaw in TOTOLINK T6 allows guest Wi-Fi tampering
CVE-2026-51687 is an incorrect access control flaw (CWE-284) in the setWiFiEasyGuestCf function of the TOTOLINK T6 router's web management interface. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi over the network, with no login or user interaction required. By exploiting it, an attacker can create a guest wireless network or weaken an existing guest network's settings, which could let the attacker gain or extend access to the guest Wi-Fi and alter the router's wireless configuration. The issue affects TOTOLINK T6 devices running firmware 4.1.5cu.748_B20211015, particularly units whose web UI is reachable from untrusted networks. Exploitation is not currently known to be in the wild: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% probability of exploitation within 30 days.
What to do: Check T6 firmware versions against 4.1.5cu.748_B20211015 and install a corrected firmware from TOTOLINK's official download/support site when it becomes available (no fixed version is specified in the data). Until patched, do not expose the router's web management interface to the WAN: disable remote management and restrict /cgi-bin/cstecgi.cgi access to the trusted LAN. Also review current guest network settings for unexpectedly created guest SSIDs or weakened security configurations that could indicate exploitation.
| TOTOLINK T6 | firmware 4.1.5cu.748_B20211015 (the only version confirmed affected in the data; other firmware versions were not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.