CVE-2026-51610: TOTOLINK T6 vulnerability
Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK T6to a version that resolves this vulnerability.Fixed in 4.1.5cu.748_B20211015 - Compensating control
Block access to /cgi-bin/cstecgi.cgi (and /cgi-bin/ endpoints) at the network layer or web server for unauthenticated users until the device is updated.
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated attacker able to send a crafted POST request to the router's CGI endpoint can trigger the reboot. The description does not state that prior authentication or administrative access is required.
What is the practical impact of exploitation?
An attacker can force the affected device to reboot immediately. This can interrupt network connectivity and may be repeatable if the attacker retains access to the CGI endpoint.
How can I determine whether a device is affected?
The affected product and firmware identified in the available data are TOTOLINK T6 running 4.1.5cu.748_B20211015. Exposure also depends on whether an attacker can reach /cgi-bin/cstecgi.cgi on the device.