CVE-2026-51700
largeUnauthenticated access control flaw in TOTOLINK T6 permits wireless tampering
CVE-2026-51700 is an incorrect access control flaw (CWE-284) in the setWiFiAdvancedCfg function of the TOTOLINK T6 wireless router, documented against firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the router's web management interface sends a crafted POST request to /cgi-bin/cstecgi.cgi, and the setWiFiAdvancedCfg handler processes it without verifying the caller's identity. The attacker gains the ability to alter the WiFi advanced configuration remotely and without credentials, degrading the device's wireless behavior; the flaw is scored Critical (CVSS 3.1: 9.1, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) even though the described impact is configuration tampering rather than code execution. Any network where an affected T6's management interface is reachable, including LAN clients and WAN-facing deployments with remote management enabled, is exposed. There is currently no known public proof-of-concept, no CISA KEV listing, and EPSS assigns a 0.4% probability of exploitation within 30 days (30th percentile), so exploitation is not known to be occurring.
What to do: Inventory for TOTOLINK T6 routers and check the running firmware version; if it is 4.1.5cu.748_B20211015, check TOTOLINK's support/download site for a newer release, since no fixed version is identified in the available data. Until patched, do not expose the router's management interface to the WAN (disable remote management) and restrict administration to trusted LAN or management-VLAN clients, because exploitation requires no authentication or user interaction. Monitor for unauthenticated POST requests to /cgi-bin/cstecgi.cgi referencing setWiFiAdvancedCfg as indicators of probing or tampering.
| TOTOLINK T6 wireless router | 4.1.5cu.748_B20211015 (build cited in the advisory; no fixed version identified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.