Junglewise Threat Intelligence

CVE-2026-51728: TOTOLINK T6 unauthenticated firmware upload in UploadFirmwareFile

CVE-2026-51728 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a network router that manages internet connectivity and wireless networks. This vulnerability allows attackers to upload malicious firmware without authentication, gaining complete control over the device and all connected networks. A successful exploit can result in permanent device compromise, network takeover, and access to all data passing through the router.

Technical details

The vulnerability is an authentication bypass (missing access control) in the UploadFirmwareFile function of the cstecgi.cgi CGI script in TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can craft and send a malicious POST request to /cgi-bin/cstecgi.cgi to upload a firmware image without credentials. The function does not validate authentication before accepting the firmware upload, allowing arbitrary firmware installation. This vulnerability is remotely exploitable over the network and requires no user interaction or authentication, giving attackers the ability to completely compromise the device.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References