CVE-2026-51733: TOTOLINK T6 vulnerability
Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Verify and re-create any Wi-Fi schedule entries that may have been removed through exploitation of the FirmwareUpgrade function.
TOTOLINK T6 4.1.5cu.748_B20211015 Wi-Fi schedule entries = remove - Compensating control
Block access to /cgi-bin/cstecgi.cgi (and related CGI endpoints) at the network edge (e.g., firewall/WAF/ACL) to prevent unauthenticated crafted POST requests.
Event History
Frequently Asked Questions
Which deployments are affected?
The affected product and version identified are TOTOLINK T6 firmware 4.1.5cu.748_B20211015. The issue is in the FirmwareUpgrade function exposed through /cgi-bin/cstecgi.cgi.
Does exploitation require authentication?
No. An unauthenticated attacker can exploit the issue by sending a crafted POST request to /cgi-bin/cstecgi.cgi.
What can an attacker do through this vulnerability?
An attacker can remove Wi-Fi schedule entries. The provided information does not establish additional impact beyond deletion of those entries.