Junglewise Threat Intelligence

CVE-2026-51610: TOTOLINK T6 unauthenticated reboot via access control bypass

CVE-2026-51610 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a wireless router used to provide internet connectivity in homes and small offices. The device's reboot function lacks proper access controls, allowing attackers on the network to force an immediate device restart without any authentication, disrupting connectivity and operations.

Technical details

An access control vulnerability exists in the RebootSystem function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerability is triggered via a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. An unauthenticated attacker with network reachability to the device can trigger an arbitrary immediate reboot without authentication credentials. This results in denial of service and network unavailability. The attack requires only network access and no user interaction.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References