Junglewise Threat Intelligence

CVE-2026-51670: TOTOLINK T6 missing access control in getSlaveUpdate

CVE-2026-51670 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router device used to provide network connectivity in residential and small business environments. An unauthenticated attacker can query slave device upgrade status and manipulate upgrade operations by sending a crafted request to the web management interface, potentially disrupting service availability or enabling unauthorized firmware modifications.

Technical details

The vulnerability is an access control flaw in the getSlaveUpdate function exposed through the cstecgi.cgi CGI endpoint on TOTOLINK T6 routers. The function fails to enforce authentication before processing requests, allowing unauthenticated attackers to query slave device upgrade status and affect upgrade bookkeeping via crafted POST requests. No authentication credentials or prior system compromise is required—the vulnerable endpoint is directly accessible over the network. An attacker can exploit this to disrupt firmware updates, gather system information about slave devices, or trigger unintended state changes in the upgrade process. Patches addressing this and related missing-authentication flaws in cstecgi.cgi functions are expected from TOTOLINK.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References