Junglewise Threat Intelligence

CVE-2026-51713: TOTOLINK T6 authentication bypass in setManualDialCfg

CVE-2026-51713 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

The TOTOLINK T6 router contains a critical flaw that allows unauthenticated attackers to modify WAN dial configurations remotely. An attacker can send a specially crafted request to disable or alter the router's internet connection, disrupting network service for all connected devices without needing valid credentials.

Technical details

The setManualDialCfg function in the CGI handler (/cgi-bin/cstecgi.cgi) fails to enforce authentication checks, allowing unauthenticated POST requests to modify WAN dial state parameters. The vulnerability affects TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 and likely other versions. An attacker on the network (or with network access to the device) can craft a POST request to manipulate WAN configuration without providing valid credentials. This represents a missing authentication issue in a critical management function. Patch availability status is not provided in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References