Junglewise Threat Intelligence

CVE-2026-51693: TOTOLINK T6 incorrect access control in setVpnPassCfg

CVE-2026-51693 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

The TOTOLINK T6 router contains an unauthenticated access control flaw in its VPN configuration function that allows any attacker on the network to weaken or disable VPN security filtering. This exposes traffic that should be protected by VPN encryption and could allow unauthorized network access, traffic interception, and potential data exfiltration from users relying on the VPN for security.

Technical details

The vulnerability is an incorrect access control flaw in the setVpnPassCfg function within the cstecgi.cgi CGI script on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerable endpoint accepts unauthenticated HTTP POST requests to /cgi-bin/cstecgi.cgi, allowing an attacker with network access to craft malicious requests that modify VPN password configuration settings. The flaw permits weakening or disabling edge filtering mechanisms that protect VPN traffic. An attacker on the local network or with network reachability to the device can exploit this without credentials or user interaction. A patch or firmware update is recommended to implement proper authentication checks before allowing configuration changes.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References