CVE-2026-51703: TOTOLINK T6 vulnerability
Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to alter when Wi-Fi is available via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
Which devices are affected?
The affected product identified in the available data is the TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015.
Does an attacker need to authenticate before exploiting this issue?
No. The issue allows unauthenticated attackers to change the Wi-Fi schedule configuration.
What access does an attacker need to exploit it?
An attacker must be able to send a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint. The available data does not state whether this endpoint is exposed beyond the local network.
What is the likely impact of successful exploitation?
An attacker can alter the times when Wi-Fi is available, which could disrupt wireless connectivity for users of the affected device.