ZeroHour

CVE-2026-51722

moderate

Unauthenticated access-control flaw in TOTOLINK T6 allows Wi-Fi upstream hijack

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an incorrect access-control flaw (CWE-284) in the setWiFiRepeaterCfg function of its web management interface. An unauthenticated attacker who can reach the device's management endpoint can send a crafted POST request to /cgi-bin/cstecgi.cgi that silently rewrites the repeater's upstream Wi-Fi configuration without logging in. By repointing the T6 to an attacker-controlled access point, the attacker inserts themselves into the path of the device's wireless traffic, enabling interception and tampering with data in transit, which is reflected in the CVSS 9.1 score's high confidentiality and integrity impact. Any deployment running the affected firmware is exposed, with risk highest where the management interface is reachable from untrusted LAN segments or from the internet. No public proof-of-concept is known, EPSS currently estimates only about a 0.3% probability of exploitation within 30 days, and the flaw is not in CISA's KEV.

What to do: Check T6 devices for firmware 4.1.5cu.748_B20211015 and apply a newer TOTOLINK firmware release as soon as one addressing this issue is available. Until then, restrict the management interface to trusted LAN segments, disable WAN-side/remote management, and prevent unauthenticated access to /cgi-bin/cstecgi.cgi from untrusted networks. Also review the currently configured repeater upstream SSID/credentials for unauthorized changes.

Affected
TOTOLINK T6firmware 4.1.5cu.748_B20211015 (named version confirmed affected; the full range of other affected versions is not documented in the available data)
Estimated exposure
moderatelikely tens of thousands of deployed T6 units worldwide (model-level install and internet-exposure counts not published) — TOTOLINK is a widely distributed budget networking brand across Asian, Middle Eastern, and Latin American markets, and the T6 repeater/mesh product has seen broad retail distribution, but no public scan or install-base counts exist for…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.