Junglewise Threat Intelligence

CVE-2026-51740: TOTOLINK T6 incorrect access control in killProcess

CVE-2026-51740 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a WiFi router used in home and small business networks. An unauthenticated attacker can send a crafted web request to terminate critical router services, causing the device to become unavailable and disrupting internet connectivity for all connected users.

Technical details

The vulnerability is an incorrect access control flaw in the killProcess function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerable endpoint /cgi-bin/cstecgi.cgi fails to properly validate user authentication before allowing callers to terminate system processes. An unauthenticated attacker can send a POST request to this endpoint to invoke killProcess and terminate critical services. The attack requires network access to the router's web interface but no prior authentication or special privileges. Successful exploitation leads to denial of service by shutting down essential router functions.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References