CVE-2026-51733
moderateUnauthenticated access-control flaw in TOTOLINK T6 allows Wi-Fi schedule deletion
CVE-2026-51733 is an incorrect access control issue (CWE-284) in the FirmwareUpgrade handler of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015, which fails to require authentication for that function. An unauthenticated attacker can trigger it by sending a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint. The documented impact is the ability to delete the router's Wi-Fi schedule entries, disrupting scheduled wireless availability; despite the critical 9.8 CVSS score (C:H/I:H/A:H), no broader compromise is described in the published data. Any TOTOLINK T6 unit running this firmware build is affected, particularly where the web management interface is reachable from untrusted or internet-facing networks. No public proof-of-concept, no CISA KEV listing, and a low 0.4% EPSS indicate exploitation has not yet been observed.
What to do: Check the firmware version in the TOTOLINK T6 administration page and, if it is 4.1.5cu.748_B20211015, avoid exposing the web management interface to the WAN and restrict access to trusted management hosts until TOTOLINK publishes a patched build. Since no fixed version is documented in the available data, review the device's Wi-Fi schedule for unexplained deletions and monitor the vendor's support site for a firmware update.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (the only firmware version listed in the advisory; other versions unverified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.