Junglewise Threat Intelligence

CVE-2026-51738: TOTOLINK T6 LoadDefSettings authentication bypass

CVE-2026-51738 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router used by consumers and businesses to provide network connectivity. An unauthenticated attacker can reset the device to factory defaults and force a reboot by sending a specially crafted network request, causing complete loss of network service and potentially enabling unauthorized reconfiguration of the network.

Technical details

The LoadDefSettings function in the cstecgi.cgi CGI script is missing authentication checks, allowing unauthenticated HTTP POST requests to trigger device reset and reboot operations. An attacker on the network (or with network access to the device's web interface on port 80/443) can craft and send a malicious POST request to /cgi-bin/cstecgi.cgi without providing credentials. Successful exploitation results in the device reverting to factory default configuration and rebooting, denying legitimate users network access and potentially enabling the attacker to reconfigure the device for malicious purposes. Patches are not mentioned in the available advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References