Junglewise Threat Intelligence

CVE-2026-51676: TOTOLINK T6 authentication bypass in setAccessDeviceCfg

CVE-2026-51676 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

The TOTOLINK T6 is a wireless router used to provide internet connectivity and network management for homes and small offices. A critical flaw in the device's web interface allows attackers on the network to remotely modify access device policies without any authentication, potentially enabling unauthorized network access control or device lockout.

Technical details

The setAccessDeviceCfg function in the TOTOLINK T6 web CGI interface (/cgi-bin/cstecgi.cgi) lacks proper authentication checks, allowing unauthenticated attackers to send crafted POST requests that alter access-device configuration policies. The vulnerability is network-accessible and requires no prior authentication or user interaction. An attacker can exploit this to modify device access controls, potentially blocking legitimate users or enabling unauthorized access. The affected firmware version is 4.1.5cu.748_B20211015; patch status is unknown from available sources.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References