Junglewise Threat Intelligence

CVE-2026-51712: TOTOLINK T6 incorrect access control in setApWiFiSchCfg

CVE-2026-51712 · Severity: medium · CVSS 5.9 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a residential WiFi router. An unauthenticated attacker can send a specially crafted request to alter the wireless availability schedule, potentially disabling or restricting internet access to connected devices without authorization.

Technical details

The setApWiFiSchCfg function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks proper authentication checks. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi to modify wireless scheduling parameters, altering when the WiFi is available. The vulnerability requires network access to the device's web interface but does not require authentication or user interaction. An attacker can modify wireless availability windows, potentially disrupting network access for legitimate users.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References