Junglewise Threat Intelligence

CVE-2026-51679: TOTOLINK T6 setPasswordCfg unauthenticated admin account takeover

CVE-2026-51679 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

The TOTOLINK T6 router is a wireless networking device used to provide internet connectivity and network services to homes and offices. An unauthenticated attacker can send a specially crafted web request to remotely change the administrator account credentials, gaining complete control over the device and enabling them to modify network settings, intercept traffic, or lock out legitimate users.

Technical details

This vulnerability is an authentication bypass and privilege escalation flaw in the setPasswordCfg function exposed via the /cgi-bin/cstecgi.cgi endpoint on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerable function fails to validate user authentication before allowing administrative password changes, allowing an unauthenticated attacker to send a POST request to change the admin account password. No authentication credentials or special preconditions are required—the vulnerability is accessible over the network to anyone with network access to the device. Successful exploitation results in complete device compromise and loss of administrative control for the legitimate owner.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References