Junglewise Threat Intelligence

CVE-2026-51727: TOTOLINK T6 incorrect access control in SystemSettings

CVE-2026-51727 · Severity: medium · CVSS 5.3 · Published 2026-08-31

Executive brief

The TOTOLINK T6 router's SystemSettings administrative function fails to verify user authentication before processing requests. An attacker on the network can craft a simple HTTP request to retrieve sensitive administrative endpoint information, including import and export credentials, without needing to log in. This exposure allows unauthorized access to critical system configuration data.

Technical details

An incorrect access control vulnerability exists in the SystemSettings function within the cstecgi.cgi CGI endpoint of the TOTOLINK T6 router. The vulnerability allows unauthenticated POST requests to /cgi-bin/cstecgi.cgi to retrieve administrative configuration and endpoint information. The root cause is a missing authentication check before processing user-supplied parameters. An attacker with network access to the router (either local or remote depending on network topology) can send a crafted POST request to extract administrative import/export credentials and other sensitive system settings without authentication. No patch has been publicly released as of the advisory date.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References