← Back to overview

CVE-2026-51725 describes an incorrect access control vulnerability in the NTPSyncWithHost function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to manipulate the device's system clock by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication is required to exploit this vulnerability, making it trivially accessible to any attacker with network access to the device. Manipulation of the device clock can have downstream effects on time-sensitive security mechanisms such as certificate validation, logging accuracy, and scheduled tasks. The vulnerability was coordinated and disclosed via GitHub repositories associated with CVE vendor coordination efforts. TOTOLINK's official website and firmware download pages are referenced as part of the disclosure. This issue highlights ongoing access control weaknesses in consumer and SOHO router firmware from TOTOLINK.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Related CVE's

  • CVE-2026-51725

Categories

  • Mobile & IoT
  • Network Infrastructure