Junglewise Threat Intelligence

CVE-2026-51683: TOTOLINK T6 auth bypass in setLanCfg

CVE-2026-51683 · Severity: medium · CVSS 4.3 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router used to provide internet connectivity in homes and small offices. An unauthenticated attacker can remotely change the router's LAN network configuration by sending a crafted request, potentially isolating devices from the network or redirecting traffic through the attacker's system.

Technical details

The setLanCfg function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks authentication controls, allowing unauthenticated POST requests to the web interface endpoint /cgi-bin/cstecgi.cgi to modify LAN settings. An attacker on the network or with network access to the router can alter the LAN configuration without credentials. This is an access control bypass vulnerability (CWE-287) affecting a CGI administrative function. No authentication is required, making exploitation trivial from any network-adjacent position.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References