CVE-2026-51680: Critical severity TOTOLINK T6 vulnerability
Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
Which devices are affected?
The issue is reported in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The provided information does not establish whether other T6 firmware versions or other TOTOLINK models are affected.
Does exploitation require authentication or access to the router administration interface?
No authentication is required. An attacker can exploit the issue by sending a crafted POST request to /cgi-bin/cstecgi.cgi targeting the setLedCfg function.
What can an attacker change through this vulnerability?
The reported impact is modification of the device's LED behavior. The provided information does not indicate that this issue grants configuration changes beyond LED settings or broader device control.