CVE-2026-51688
Unauthenticated access control flaw in TOTOLINK T6 router enables wireless DoS
CVE-2026-51688 is an improper access control flaw (CWE-284) in the setWiFiSignalCfg handler of the TOTOLINK T6 router's web management interface, firmware 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the router's HTTP service sends a crafted POST request to /cgi-bin/cstecgi.cgi, which invokes setWiFiSignalCfg without any authentication or authorization check. The attacker gains no code execution or data access; the impact is availability-focused, allowing the Wi-Fi signal/power configuration to be degraded or the device to be crashed into a denial of service. Only TOTOLINK T6 devices running the affected firmware are known to be impacted, and devices whose management interface is reachable only from the local LAN are largely shielded unless the attacker is already on the network or WAN-side remote management is enabled. There are no reports of in-the-wild exploitation, no public proof of concept, the flaw is not in CISA's KEV, and EPSS assigns it roughly a 0.4% probability of exploitation within 30 days.
What to do: Owners should check whether their TOTOLINK T6 runs firmware 4.1.5cu.748_B20211015 and apply the vendor's fixed firmware when TOTOLINK publishes an update (no fixed version is documented in the available data). Until then, disable WAN-side/remote management and restrict the web UI to trusted LAN segments, since exploitation only requires unauthenticated reachability of /cgi-bin/cstecgi.cgi. Treat expected impact as availability loss — reduced Wi-Fi transmit power or router crashes — rather than data theft, and monitor for unauthenticated POST requests to that endpoint.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (only version confirmed in the advisory; other firmware versions unverified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS) via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.