CVE-2026-51732: TOTOLINK T6 vulnerability
Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK T6to a version that resolves this vulnerability.Fixed in 4.1.5cu.748_B20211015
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker does not need to authenticate. Exploitation requires sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint.
What is the impact of a successful attack?
An attacker can remove Wi-Fi schedule entries through the delWiFiScheduleCfg function. The provided information does not indicate that the issue enables changes beyond deleting those entries.
How can I tell whether a device may be affected?
The affected product and firmware identified in the available data are TOTOLINK T6 running 4.1.5cu.748_B20211015. Devices exposing the specified CGI endpoint may be reachable by an unauthenticated attacker if that endpoint is accessible to them.