Junglewise Threat Intelligence

CVE-2026-51684: TOTOLINK T6 incorrect access control in setStorageCfg

CVE-2026-51684 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a network router that manages storage and connectivity settings. An authentication vulnerability in the storage configuration function allows unauthenticated attackers on the network to remotely disable or modify storage services, potentially disrupting business continuity and data access for all connected users.

Technical details

The setStorageCfg function in cstecgi.cgi (a CGI script handling device configuration) lacks proper authentication checks. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke setStorageCfg and alter storage-related service state without credentials. The attack requires only network reachability to the affected device and no user interaction. Successful exploitation allows modification of storage configuration, leading to potential service disruption or data access changes.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References