CVE-2026-51668: TOTOLINK T6 vulnerability
Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to /cgi-bin/cstecgi.cgi and the endpoint that triggers setLanguageCfg (language configuration via /cgi-bin/cstecgi.cgi) to authenticated users only, using an external control such as network ACL/firewall rules to block unauthenticated inbound access.
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker who can send a crafted POST request to the affected device's /cgi-bin/cstecgi.cgi endpoint can modify its language configuration. No login is required.
Which configuration changes are exposed?
The affected setLanguageCfg function allows modification of the device language configuration. The provided information does not indicate access to other configuration settings.
How can I determine whether a device is affected?
The reported affected firmware is TOTOLINK T6 version 4.1.5cu.748_B20211015. Devices running that version should be treated as affected.