Junglewise Threat Intelligence

CVE-2026-51666: TOTOLINK T6 missing authentication in setWizardCfg

CVE-2026-51666 · Severity: medium · CVSS 4.3 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router used in home and small office networks. An unauthenticated attacker can remotely reconfigure critical settings including WAN connection, Wi-Fi parameters, and device initialization without any login credentials, potentially disrupting network connectivity or changing security configurations.

Technical details

The vulnerability is an authentication bypass in the setWizardCfg function of the cstecgi.cgi web interface in TOTOLINK T6firmware 4.1.5cu.748_B20211015. An attacker can send a crafted HTTP POST request to /cgi-bin/cstecgi.cgi without authentication to modify WAN, Wi-Fi, and device initialization settings. The vulnerability requires only network reachability to the router's web interface (default port 80) and no user interaction. An attacker can modify network configurations, change Wi-Fi SSID/password, or reset initialization state, effectively compromising device functionality and security. No patch status is currently known from the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References