Junglewise Threat Intelligence

CVE-2026-51696: TOTOLINK T6 missing access control in setPortForwardRules

CVE-2026-51696 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

TOTOLINK T6 routers contain a port forwarding configuration function that does not require authentication. An attacker on the network can send a crafted request to reconfigure port forwarding rules, exposing internal services to the internet and enabling unauthorized access to devices behind the router.

Technical details

The setPortForwardRules function in cstecgi.cgi lacks proper authentication checks, allowing unauthenticated access via POST requests to /cgi-bin/cstecgi.cgi. This is an access control vulnerability in the router's web management interface. An attacker with network access to the device can modify port forwarding rules without credentials, potentially exposing internal services and systems. The vulnerability affects TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 and requires only network reachability to the router's management interface.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References