Junglewise Threat Intelligence

CVE-2026-51702: TOTOLINK T6 incorrect access control in setIpPortFilterRules

CVE-2026-51702 · Severity: medium · CVSS 4.3 · Published 2026-08-31

Executive brief

The TOTOLINK T6 router's web interface contains a vulnerability that allows unauthenticated attackers to modify firewall policies without logging in. An attacker on the network can send a specially crafted request to bypass authentication checks and alter IP and port filtering rules, potentially opening the firewall to allow malicious traffic or block legitimate communications.

Technical details

The vulnerability is an authentication bypass / incorrect access control flaw in the setIpPortFilterRules function within the cstecgi.cgi web interface component of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The affected endpoint at /cgi-bin/cstecgi.cgi fails to properly validate user authentication before processing POST requests to modify firewall rules. An unauthenticated attacker with network access can send a crafted POST request to alter IP and port filter configurations, effectively gaining unauthorized administrative control over the device's firewall policies. No authentication bypass mitigation or user interaction is required. A firmware patch would be required to restore proper access controls.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References