Junglewise Threat Intelligence

CVE-2026-51689: TOTOLINK T6 firmware upgrade unauthenticated access control bypass

CVE-2026-51689 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

The TOTOLINK T6 router's firmware upgrade function lacks proper authentication checks, allowing attackers on the network to trigger firmware updates without credentials. An attacker could initiate unauthorized firmware changes by sending a specially crafted request to the device's web interface, potentially installing malicious firmware or causing the device to malfunction and disrupting all internet access for affected users.

Technical details

The vulnerability is an authentication bypass in the setUpgradeFW function of the TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. The vulnerable endpoint is /cgi-bin/cstecgi.cgi, which processes firmware upgrade requests via HTTP POST without verifying user credentials. An unauthenticated attacker with network access to the router can craft a malicious POST request to trigger firmware upgrade operations, potentially replacing the legitimate firmware with compromised code or causing denial of service. The attack requires no user interaction or prior authentication, making it trivially exploitable by any attacker on the same network or via WAN if the web interface is exposed.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed
  • 2026-08-31: advisory: CVE-2026-51689 published

References