Junglewise Threat Intelligence

CVE-2026-51733: TOTOLINK T6 access control bypass in FirmwareUpgrade

CVE-2026-51733 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router used in home and small business networks. An unauthenticated attacker can modify the device's Wi-Fi schedule configuration by sending a crafted request to the web interface, allowing them to disable or alter Wi-Fi scheduling rules without any authentication credentials.

Technical details

The FirmwareUpgrade function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks proper access control validation, allowing unauthenticated attackers to modify device settings. The vulnerability exists in the /cgi-bin/cstecgi.cgi endpoint, which accepts POST requests without verifying the caller's authentication status. An attacker on the network can send a crafted POST request to remove or modify Wi-Fi schedule entries, causing service disruption. The vulnerability requires network access to the router's web interface but no user interaction or credentials. A patch or updated firmware version may be available from TOTOLINK.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References