CVE-2026-51680 describes an incorrect access control vulnerability in the setLedCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to modify LED behavior on the affected device by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication or credentials are required to exploit this vulnerability, making it trivially accessible to any attacker with network access to the device. The vulnerability stems from missing or improperly enforced access controls on a sensitive CGI function. While the immediate impact appears limited to LED configuration changes, the pattern of unauthenticated CGI access could indicate broader attack surface concerns on this device. TOTOLINK T6 is a consumer/SOHO networking device, and such vulnerabilities are commonly targeted in IoT-focused botnet campaigns.