Junglewise Threat Intelligence

CVE-2026-51678: TOTOLINK T6 setSyslogCfg missing authentication

CVE-2026-51678 · Severity: medium · CVSS 4.3 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router used in homes and small offices. An unauthenticated attacker can send a crafted web request to alter the device's logging configuration, potentially disabling audit trails or redirecting logs to attacker-controlled servers. This could allow an attacker to hide their tracks while conducting further attacks on the device or connected network.

Technical details

The setSyslogCfg function in the cstecgi.cgi web interface lacks proper authentication checks, resulting in an access control vulnerability. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi with crafted parameters to modify syslog configuration settings. No authentication or session token is required to invoke this function, making it accessible over the network to any attacker. Successful exploitation allows an attacker to alter logging behavior, potentially disabling forensic capabilities or redirecting logs off-device. Patch availability depends on TOTOLINK's response to the vulnerability disclosure.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References