CVE-2026-51686: TOTOLINK T6 vulnerability
Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block access to /cgi-bin/cstecgi.cgi from unauthenticated clients (e.g., via firewall/ACL/WAF rules) to prevent crafted POST requests from reconfiguring or disabling wireless networks.
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Devices running TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 are exposed if an attacker can send HTTP POST requests to the device's web management interface.
Does an attacker need to authenticate first?
No. The vulnerable setWiFiEasyCfg function can be reached without authentication using a crafted POST request to /cgi-bin/cstecgi.cgi.
What could an attacker do through this issue?
An unauthenticated attacker can reconfigure wireless networks or disable them, potentially disrupting Wi-Fi connectivity.