CVE-2026-51691: TOTOLINK T6 vulnerability
Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
The affected product and firmware identified in the available data are TOTOLINK T6 running version 4.1.5cu.748_B20211015. Exposure requires that an attacker can send requests to the device's web management CGI endpoint.
Does exploitation require authentication?
No. The issue is described as exploitable by unauthenticated attackers using a crafted POST request to /cgi-bin/cstecgi.cgi.
What capability does successful exploitation provide?
An attacker can manipulate the device's upload or flash workflow through the setUploadSetting function. The available information does not specify whether this results in firmware replacement, code execution, or another final impact.