ZeroHour

CVE-2026-51709

large

Unauthenticated Wi-Fi configuration tampering in TOTOLINK T6 router firmware

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51709 is a broken access control flaw (CWE-284) in the setWiFiBasicCfg function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint without logging in. Successful exploitation lets the attacker rewrite the router's primary Wi-Fi settings (for example the network name or wireless security configuration), which can disrupt connectivity for all connected clients and potentially push them onto attacker-influenced networks; the flaw carries a critical CVSS 3.1 score of 9.8. Affected users are those running the T6 on the listed firmware build; other firmware revisions are not confirmed in the available data. There is currently no public proof-of-concept, the CVE is not in CISA's KEV, and EPSS assigns it only a 0.4% probability of exploitation in the next 30 days, so no exploitation is confirmed.

What to do: Check the T6's firmware version on the device status page and upgrade via TOTOLINK's support site when a fixed build is published (no fixed version is confirmed in the available data). In the meantime, disable WAN-side/remote web management or restrict access to the management interface so /cgi-bin/cstecgi.cgi is not reachable from the internet, and verify that the primary Wi-Fi SSID and password settings have not been unexpectedly changed.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the build named in the advisory; no other versions confirmed)
Estimated exposure
largelikely in the low tens of thousands of internet-exposed devices (estimate; no published scan count for this exact model) — TOTOLINK budget routers routinely appear in public Shodan/FOFA internet scans in the tens-of-thousands range, and the T6 is one of the brand's widely sold entry-level models, so a low five-figure exposed-device count is plausible though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.