CVE-2026-51670: TOTOLINK T6 vulnerability
Published Aug 31, 2026
·Updated
Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
1 affected component
TOTOLINK T6=4.1.5cu.748_B20211015
Event History
Aug 31, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:17 PM
Description
Frequently Asked Questions
1
Which device and firmware release are confirmed affected?
The affected product is TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015.
2
Does an attacker need to authenticate before exploiting this issue?
No. The issue allows unauthenticated attackers to send a crafted POST request to /cgi-bin/cstecgi.cgi.
3
What can an attacker do through the vulnerable function?
An attacker can query slave upgrade status and affect slave upgrade bookkeeping through the getSlaveUpdate function.