Junglewise Threat Intelligence

CVE-2026-51709: TOTOLINK T6 unauthenticated Wi-Fi reconfiguration

CVE-2026-51709 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a residential router/gateway device. An unauthenticated attacker can reconfigure primary Wi-Fi settings (such as SSID and password) without any authentication, by sending a crafted request to the device's web administration interface. This allows an attacker to lock legitimate users off the network and redirect traffic through a modified access point.

Technical details

The vulnerability is an access control flaw (CWE-284) in the setWiFiBasicCfg function of the cstecgi.cgi CGI script. The function fails to require authentication before allowing Wi-Fi configuration changes. An attacker can send an HTTP POST request to /cgi-bin/cstecgi.cgi from the network to modify primary Wi-Fi parameters. No authentication credentials, session token, or user interaction is required. The attack is possible from any device with network access to the router (e.g., through an open Wi-Fi network or downstream LAN device). No patch status is publicly documented.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References