← Terug naar overzicht

CVE-2026-51725 describes an incorrect access control vulnerability in the NTPSyncWithHost function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to manipulate the device's system clock by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication or credentials are required to exploit this vulnerability, making it trivially accessible to attackers. Manipulation of the device clock can have downstream effects on time-sensitive security functions such as certificate validation, logging, and scheduled tasks. The vulnerability was disclosed via GitHub repositories coordinating CVE vendor communication and is listed on the NVD. TOTOLINK has been notified through coordinated disclosure efforts. The affected product is a consumer/SOHO router, placing it in the IoT and network infrastructure risk category. Users are advised to check for firmware updates or apply mitigations as available.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Related CVE's

  • CVE-2026-51725

Categories

  • Mobile & IoT
  • Network Infrastructure