CVE-2026-51681 describes an incorrect access control vulnerability in the setRemoteCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to expose WAN-side administration interfaces by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication is required to exploit this vulnerability, significantly lowering the attack barrier. Successful exploitation could allow attackers to gain administrative access to the router from the WAN side, potentially enabling full device compromise. The vulnerability was disclosed via NVD and coordinated through GitHub repositories by researchers DarkBoulder and ShengWu00. TOTOLINK has been notified as part of vendor coordination efforts. The affected product is a consumer/SOHO router, making it a risk for both home and small business environments. Mitigation likely involves a firmware update from TOTOLINK.
/cgi-bin/cstecgi.cgi