Junglewise Threat Intelligence

CVE-2026-51673: TOTOLINK T6 incorrect access control in setNtpCfg

CVE-2026-51673 · Severity: high · CVSS 7.5 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router used to provide network connectivity in homes and small offices. An unauthenticated attacker can remotely modify the device's time synchronization settings via a web request, potentially disrupting network operations, breaking certificate validation, and interfering with time-dependent services and logging.

Technical details

The vulnerability is an authentication bypass in the setNtpCfg function of the cstecgi.cgi web interface on TOTOLINK T6 4.1.5cu.748_B20211015. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to modify NTP (Network Time Protocol) configuration without providing valid credentials. The vulnerability requires network access to the router's web management interface (typically port 80/443) but no user interaction or prior authentication. An attacker can alter time settings, which could impact certificate validation, system logs, and time-dependent features. Patches or firmware updates may be available from TOTOLINK.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References