Junglewise Threat Intelligence

CVE-2026-51742: TOTOLINK T6 incorrect access control in discoverWan function

CVE-2026-51742 · Severity: medium · CVSS 5.9 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a WiFi router that manages network connectivity for homes and small businesses. An unauthenticated attacker can trigger WAN (wide-area network) discovery logic by sending a specially crafted request to the router's web interface, potentially disrupting network operations or gathering sensitive network configuration details without any credentials.

Technical details

The vulnerability is an authentication bypass / missing access control flaw in the discoverWan function within the cstecgi.cgi web interface handler of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated remote attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke the discoverWan function, which should have been protected with authentication checks. The router is network-accessible from the internet or local network by default, and no user interaction or credentials are required. An attacker can abuse this to trigger WAN discovery operations, potentially exposing configuration data or disrupting WAN connectivity. The advisory does not indicate patch availability at the time of publication.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References