Junglewise Threat Intelligence

CVE-2026-51717: TOTOLINK T6 incorrect access control in setOpModeCfg

CVE-2026-51717 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a residential WiFi router that manages internet connectivity and network configuration. An unauthenticated attacker can change the device's operating mode by sending a crafted request, potentially disrupting network services, redirecting traffic, or modifying critical device behavior without requiring any authentication or special access.

Technical details

The vulnerability is an access control bypass (CWE-306) in the setOpModeCfg function of the cstecgi.cgi web interface. The affected component fails to authenticate requests before allowing modifications to the device operating mode. An unauthenticated attacker can send a POST request to /cgi-bin/cstecgi.cgi to invoke setOpModeCfg and change the device's operational state. The attack is network-reachable and requires no authentication or user interaction. This allows remote attackers to modify device configuration and potentially render the router unusable or redirect its behavior to attacker-controlled specifications. Patch information has not been disclosed.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References