Junglewise Threat Intelligence

CVE-2026-51703: TOTOLINK T6 auth bypass in WiFi scheduling via setWiFiScheduleCfg

CVE-2026-51703 · Severity: medium · CVSS 5.4 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router used in residential and small business networks. An unauthenticated attacker on the network can send a specially crafted request to disable or alter the router's Wi-Fi schedule, causing potential service disruption and loss of network availability control.

Technical details

The vulnerability is an incorrect access control flaw in the setWiFiScheduleCfg function within the cstecgi.cgi CGI script. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi to modify Wi-Fi scheduling configurations. The vulnerability requires network access to the router's administration interface but no authentication credentials. Successful exploitation allows an attacker to alter when the Wi-Fi radio is available, disrupting network connectivity without authorization. No information on patch availability is provided in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References