ZeroHour

CVE-2026-51688

Unauthenticated access control flaw in TOTOLINK T6 router enables wireless DoS

CVSS 3.1
7.5 high
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-51688 is an improper access control flaw (CWE-284) in the setWiFiSignalCfg handler of the TOTOLINK T6 router's web management interface, firmware 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the router's HTTP service sends a crafted POST request to /cgi-bin/cstecgi.cgi, which invokes setWiFiSignalCfg without any authentication or authorization check. The attacker gains no code execution or data access; the impact is availability-focused, allowing the Wi-Fi signal/power configuration to be degraded or the device to be crashed into a denial of service. Only TOTOLINK T6 devices running the affected firmware are known to be impacted, and devices whose management interface is reachable only from the local LAN are largely shielded unless the attacker is already on the network or WAN-side remote management is enabled. There are no reports of in-the-wild exploitation, no public proof of concept, the flaw is not in CISA's KEV, and EPSS assigns it roughly a 0.4% probability of exploitation within 30 days.

What to do: Owners should check whether their TOTOLINK T6 runs firmware 4.1.5cu.748_B20211015 and apply the vendor's fixed firmware when TOTOLINK publishes an update (no fixed version is documented in the available data). Until then, disable WAN-side/remote management and restrict the web UI to trusted LAN segments, since exploitation only requires unauthenticated reachability of /cgi-bin/cstecgi.cgi. Treat expected impact as availability loss — reduced Wi-Fi transmit power or router crashes — rather than data theft, and monitor for unauthenticated POST requests to that endpoint.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (only version confirmed in the advisory; other firmware versions unverified)
Estimated exposure
unknown; plausibly on the order of tens of thousands of T6 units in service, of which only a subset with the management web UI reachable (via LAN or WAN) is… — No public install-base or internet-scan counts exist for this single model and firmware version, so the estimate relies on TOTOLINK's profile as a budget consumer-router vendor whose devices appear in internet-wide scans in the tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS) via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.