Junglewise Threat Intelligence

CVE-2026-51687: TOTOLINK T6 incorrect access control in WiFi guest configuration

CVE-2026-51687 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

The TOTOLINK T6 router's guest wireless network management feature lacks proper authentication checks. An unauthenticated attacker can send a crafted web request to create or weaken guest WiFi access, potentially exposing the router to unauthorized network access and allowing guest network settings to be manipulated without authorization.

Technical details

The vulnerability exists in the setWiFiEasyGuestCf function within /cgi-bin/cstecgi.cgi, which fails to perform proper authentication validation before processing guest WiFi configuration changes. An attacker can send an unauthenticated HTTP POST request to this endpoint to modify guest wireless settings, including creating new guest networks or weakening security parameters. No prior authentication or special privileges are required; the attack is a straightforward network-based request. An attacker can gain unauthorized control over guest network configurations, potentially used for man-in-the-middle attacks or network reconnaissance. Patch status is not specified in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References