Junglewise Threat Intelligence

CVE-2026-51694: TOTOLINK T6 incorrect access control in setStaticDhcpRules

CVE-2026-51694 · Severity: high · CVSS 7.5 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router used to provide internet connectivity to homes and businesses. An unauthenticated attacker can send a specially crafted request to modify static DHCP configuration, potentially redirecting network traffic or disrupting device connectivity for other users on the network.

Technical details

The vulnerability is an authentication bypass in the setStaticDhcpRules function within the cstecgi.cgi CGI script on TOTOLINK T6 routers. The vulnerable endpoint at /cgi-bin/cstecgi.cgi fails to properly validate user credentials before processing POST requests to modify static DHCP rules. An unauthenticated attacker on the network can directly send crafted POST requests to add or change DHCP rule configurations without authentication. This allows unauthorized modification of the router's DHCP static binding table, which can be leveraged to perform man-in-the-middle attacks or deny service to legitimate devices.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References