CVE-2026-51738
Broken access control in TOTOLINK T6 router enables unauthenticated reset and reboot
CVE-2026-51738 is an incorrect access-control flaw (CWE-284) in the LoadDefSettings function of the TOTOLINK T6 router's web management interface, scored critical at CVSS 3.1: 9.8. An unauthenticated attacker triggers it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, requiring no credentials or user interaction. The outcome is a reset of the device configuration to defaults plus a reboot, which disrupts connectivity and can be repeated at will; the CVSS vector scores the impact as high across confidentiality, integrity, and availability. Affected users are those running the T6 with firmware 4.1.5cu.748_B20211015, the build named in the advisory; whether other builds are affected is not documented in the available data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only a 0.4% probability of exploitation within 30 days.
What to do: No fixed firmware version is identified in the available data, so check TOTOLINK's support site for an updated T6 build. Until patched, keep the web management interface off the WAN and restrict access to trusted LAN clients, since the attack requires only unauthenticated HTTP reachability to the router. Treat unexpected factory-default resets or reboots as possible signs of exploitation and verify your running firmware version.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the build named in the advisory; the full range of affected firmware is not documented in the provided data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.