← Back to overview

CVE-2026-51680 is an incorrect access control vulnerability discovered in the setLedCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to modify the device's LED behavior by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication or credentials are required to exploit this vulnerability, making it trivially accessible to any attacker with network access to the device. The vulnerability stems from insufficient access controls on a CGI-based web interface function. TOTOLINK T6 is a consumer/SOHO network router, meaning exploitation could affect home and small business environments. Proof-of-concept and vendor coordination details have been published on GitHub by security researchers. The vendor's official website and firmware download pages have been referenced as part of the disclosure.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Related CVE's

  • CVE-2026-51680

Categories

  • Mobile & IoT
  • Network Infrastructure