Junglewise Threat Intelligence

CVE-2026-51698: TOTOLINK T6 incorrect access control in setUrlFilterRules

CVE-2026-51698 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a router used to manage network traffic and control user access. The device fails to properly authenticate requests to change browsing policies, allowing an attacker on the network to remotely modify which websites users can access without needing a password. This could disrupt normal business operations and compromise network security.

Technical details

The vulnerability is an authentication bypass (incorrect access control) in the setUrlFilterRules function of the cstecgi.cgi web interface. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to modify URL filtering rules and alter browsing policies. No credentials or prior authentication are required; the attack is network-accessible and can be exploited by any attacker with network connectivity to the device's management interface. The impact is complete compromise of browsing policy controls.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References