CVE-2026-51675: TOTOLINK T6 vulnerability
Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to /cgi-bin/cstecgi.cgi (and related WAN configuration endpoints) so only authenticated/authorized administrative clients can reach it (e.g., via firewall/ACL/WAF).
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of the TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015 are identified as affected. The vulnerable function can be reached through the device's CGI endpoint.
What does an attacker need to exploit it?
An attacker does not need to authenticate. Exploitation requires sending a crafted POST request to /cgi-bin/cstecgi.cgi targeting the setWanIeCfg function.
What could an attacker change?
The issue allows an unauthenticated attacker to reconfigure the router's uplink settings.