Junglewise Threat Intelligence

CVE-2026-51695: TOTOLINK T6 authentication bypass in setDdnsCfg

CVE-2026-51695 · Severity: high · CVSS 7.5 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a home wireless router that manages network connectivity and dynamic DNS settings. This vulnerability allows attackers on the network to modify dynamic DNS configuration without any authentication, potentially redirecting the device's domain name to malicious locations or causing service disruption.

Technical details

The setDdnsCfg function in the cstecgi.cgi web interface lacks proper authentication checks, allowing unauthenticated POST requests to alter dynamic DNS configuration. The vulnerability exists in firmware version 4.1.5cu.748_B20211015. An attacker with network access to the device's web interface can craft a malicious POST request to /cgi-bin/cstecgi.cgi to modify DDNS settings without credentials. No patch information is currently available.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References