Junglewise Threat Intelligence

CVE-2026-51699: TOTOLINK T6 authentication bypass in setDmzCfg

CVE-2026-51699 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

The TOTOLINK T6 router's DMZ (demilitarized zone) configuration function lacks proper authentication checks, allowing unauthenticated attackers to modify DMZ settings and expose internal network hosts to the internet. An attacker can send a crafted request to the router's web interface to change which internal host is exposed, potentially redirecting traffic or creating a security perimeter bypass.

Technical details

The setDmzCfg function in the TOTOLINK T6 firmware (version 4.1.5cu.748_B20211015) accessible via the /cgi-bin/cstecgi.cgi endpoint fails to validate authentication credentials before processing DMZ configuration requests. The vulnerability is reachable via unauthenticated HTTP POST requests from the network. An attacker can exploit this to modify the DMZ IP address configuration, redirecting external traffic destined for the router to an arbitrary internal host on the LAN. This is part of a broader set of authentication bypass issues in this firmware version affecting multiple CGI functions.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References