Junglewise Threat Intelligence

CVE-2026-51677: TOTOLINK T6 UPnP configuration auth bypass

CVE-2026-51677 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a consumer-grade WiFi router used to provide internet connectivity and network management for home and small office environments. An unauthenticated attacker on the network can disable or modify UPnP (a protocol used for automatic port forwarding and device discovery) settings by sending a specially crafted request to the router's configuration interface, potentially disrupting legitimate applications that rely on UPnP and exposing the network to unauthorized access.

Technical details

This vulnerability is an access control flaw (CWE-284) in the setUPnPCfg function of the cstecgi.cgi web interface. The vulnerability allows unauthenticated attackers to modify UPnP service settings by sending a crafted POST request to /cgi-bin/cstecgi.cgi without providing valid credentials. The attack vector is network-based and requires no user interaction or authentication. An attacker can enable or disable UPnP services, potentially leading to network misconfiguration and security bypass. The affected version is TOTOLINK T6 4.1.5cu.748_B20211015; patch status is unknown.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References