CVE-2026-51701: TOTOLINK T6 vulnerability
Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker who can send a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint can exploit it. The provided information does not state that authentication, local network access, or any other prerequisite is required.
What device configuration can be changed through exploitation?
The issue allows an attacker to change device access-control settings through the setMacFilterRules function. This can affect the MAC-filter rules used to control device access.
How can I determine whether a device is potentially affected?
The affected product and version identified in the data are TOTOLINK T6 running firmware 4.1.5cu.748_B20211015. Review the device model and installed firmware version to determine whether they match.