CVE-2026-51739: TOTOLINK T6 vulnerability
Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to /cgi-bin/cstecgi.cgi (e.g., block at firewall/ACL/WAF) so unauthenticated attackers cannot reach the CloudSrvVersionCheck endpoint.
Event History
Frequently Asked Questions
Which devices are affected?
The affected product identified in the available data is the TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015.
Does exploitation require authentication or local network access?
Authentication is not required. The available data states that an attacker can trigger the cloud update check by sending a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint; it does not specify network reachability requirements.
What action can an attacker perform?
An unauthenticated attacker can trigger cloud update checks through the CloudSrvVersionCheck function. The available data does not establish that the attacker can install firmware, alter update settings, or execute code.