ZeroHour

CVE-2026-51692

large

Unauthenticated access-control flaw in TOTOLINK T6 router guest Wi-Fi configuration

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-51692 is an incorrect access-control flaw (CWE-284) in the setWiFiGuestCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. Because the /cgi-bin/cstecgi.cgi endpoint that handles guest wireless configuration does not require authentication, an unauthenticated attacker who can reach the router's web interface can send a crafted POST request to establish, disable, or weaken guest wireless access. Successful exploitation requires no credentials or user interaction, so an attacker can open guest Wi-Fi to unauthorized clients or modify its configuration without any evidence in normal administration logs. Owners of TOTOLINK T6 routers running the listed firmware are affected; no other products or version ranges are named in the available data. No confirmed exploitation is known: the flaw is not in CISA's KEV, EPSS assigns roughly a 0.3% probability of exploitation within 30 days (21st percentile), and no public proof-of-concept is known.

What to do: Check the firmware version on your TOTOLINK T6 and, if it is 4.1.5cu.748_B20211015, apply patched firmware when TOTOLINK publishes a fix, since no fixed version is specified in the available data. In the meantime, reduce exposure by disabling WAN-side/remote management or firewalling the administration interface so only trusted LAN clients can reach /cgi-bin/cstecgi.cgi, and periodically verify that guest Wi-Fi settings have not been altered.

Affected
TOTOLINK T64.1.5cu.748_B20211015
Estimated exposure
largeplausibly hundreds of thousands of T6 units in use, with likely tens of thousands directly internet-exposed (exact T6 install base unpublished) — TOTOLINK is a mass-market budget router brand popular in Asia, the Middle East, and other price-sensitive markets, and public internet-wide scans of the brand have historically shown tens of thousands of exposed TOTOLINK devices, but no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.