Junglewise Threat Intelligence

CVE-2026-51725: TOTOLINK T6 NTPSyncWithHost incorrect access control

CVE-2026-51725 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a network router that manages internet connectivity and network time synchronization. An authentication bypass vulnerability in the time synchronization function allows unauthenticated attackers to remotely modify the device's system clock via a crafted web request. Clock manipulation can disrupt network services, invalidate SSL certificates, break logging and audit trails, and cause widespread operational issues across connected systems.

Technical details

The vulnerability is an authentication bypass / incorrect access control flaw in the NTPSyncWithHost function of cstecgi.cgi. The flaw allows unauthenticated attackers to send a crafted POST request to /cgi-bin/cstecgi.cgi to trigger the vulnerable function without valid credentials. No authentication is required; the attack is network-accessible and requires only the ability to send a malicious HTTP POST payload. A successful exploit results in arbitrary modification of the device's system clock. Patches or mitigations for TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 have not been confirmed as available from the vendor.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed
  • other: CVE-2026-51725 assigned

References