Junglewise Threat Intelligence

CVE-2026-51710: TOTOLINK T6 authentication bypass in setParentalRules

CVE-2026-51710 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a WiFi router with parental control features. An unauthenticated attacker can send a specially crafted web request to disable or modify parental control settings, allowing access to restricted content or removing supervision on child accounts without the administrator's knowledge or consent.

Technical details

The vulnerability is an incorrect access control flaw in the setParentalRules function of the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. The affected CGI endpoint at /cgi-bin/cstecgi.cgi does not properly authenticate incoming POST requests before allowing modification of parental control rules. An unauthenticated, network-adjacent attacker can craft and send a POST request to this endpoint to alter parental control behavior. The vulnerability requires network access to the router but no authentication credentials. Patches or vendor guidance is not mentioned in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References