Junglewise Threat Intelligence

CVE-2026-51732: TOTOLINK T6 access control bypass in delWiFiScheduleCfg

CVE-2026-51732 · Severity: medium · CVSS 5.3 · Published 2026-08-31

Executive brief

The TOTOLINK T6 router's web management interface lacks proper authentication checks on the Wi-Fi scheduling configuration deletion function. An attacker on the network can send a crafted request to disable Wi-Fi schedules without logging in, disrupting network access controls that the device administrator has configured.

Technical details

This vulnerability is an incorrect access control flaw in the delWiFiScheduleCfg function exposed via the /cgi-bin/cstecgi.cgi endpoint on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The function fails to verify authentication before processing requests to delete Wi-Fi schedule entries. An unauthenticated attacker with network access can send a POST request to trigger deletion of Wi-Fi scheduling configurations. No special credentials, user interaction, or authentication are required. The impact is limited to tampering with Wi-Fi schedule settings rather than code execution or broader system compromise. Patches or firmware updates addressing this issue are not mentioned in the available advisory information.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References