Junglewise Threat Intelligence

CVE-2026-51691: TOTOLINK T6 incorrect access control in setUploadSetting

CVE-2026-51691 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router that manages firmware updates and system configuration. An unauthenticated attacker can exploit missing access controls in the upload functionality to manipulate firmware or system files, potentially leading to unauthorized system modification, malware installation, or device takeover.

Technical details

The vulnerability is an incorrect access control issue in the setUploadSetting function of the cstecgi.cgi CGI application. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to bypass authentication and manipulate the upload or flash workflow. The vulnerability is network-reachable and requires no authentication or user interaction. A successful exploit allows an attacker to alter firmware updates, flash custom code, or modify system configurations, potentially achieving remote code execution or permanent device compromise.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References