Junglewise Threat Intelligence

CVE-2026-51739: TOTOLINK T6 auth bypass in CloudSrvVersionCheck

CVE-2026-51739 · Severity: medium · CVSS 5.9 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a router device used to provide internet connectivity and network management. An unauthenticated attacker can trigger cloud update checks on the device by sending a crafted POST request, potentially allowing them to manipulate the update process or cause denial of service without requiring any user credentials.

Technical details

This vulnerability is an incorrect access control flaw in the CloudSrvVersionCheck function of the cstecgi.cgi web interface on TOTOLINK T6 running firmware 4.1.5cu.748_B20211015. The vulnerable endpoint fails to validate authentication before processing cloud update check requests. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to trigger cloud update checks without any credentials, authentication bypass, or user interaction. This can be leveraged to manipulate the device update mechanism or cause service disruption. The vulnerability is network-reachable and requires no authentication or special privileges.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References