CVE-2026-51666: TOTOLINK T6 vulnerability
Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device initialization state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block unauthenticated access to /cgi-bin/cstecgi.cgi at the network edge (e.g., firewall/WAF/ACL), since the vulnerability in setWizardCfg in TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated reconfiguration via a crafted POST request to that endpoint.
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit it by sending a crafted POST request to the affected CGI endpoint. The description does not state that prior login or credentials are required.
What device settings could an attacker change?
The issue allows reconfiguration of WAN settings, Wi-Fi settings, and the device initialization state.
How can I determine whether a device may be affected?
The affected product and firmware identified in the data are TOTOLINK T6 running 4.1.5cu.748_B20211015. The vulnerable function is exposed through /cgi-bin/cstecgi.cgi and is named setWizardCfg.