Junglewise Threat Intelligence

CVE-2026-51700: TOTOLINK T6 incorrect access control in setWiFiAdvancedCfg

CVE-2026-51700 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

The TOTOLINK T6 router's wireless configuration function lacks proper authentication checks, allowing anyone on the network to degrade WiFi performance and reliability through unauthenticated requests. An attacker can modify advanced wireless settings without logging in, potentially disrupting internet connectivity for all users and affecting the router's operation.

Technical details

The setWiFiAdvancedCfg function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 suffers from missing authentication checks in the cstecgi.cgi web interface. Attackers can send crafted POST requests to /cgi-bin/cstecgi.cgi without authentication credentials to modify wireless advanced configuration parameters. The vulnerability is network-accessible and requires no prior authentication or user interaction. An unauthenticated attacker can degrade wireless behavior including potentially disabling WiFi, reducing performance, or changing critical WiFi settings. Patches or vendor fixes for this specific vulnerability are not mentioned in available sources.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References