← Terug naar overzicht

A critical incorrect access control vulnerability exists in the setPasswordCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to change the administrator account credentials by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication is required to exploit this vulnerability, making it particularly dangerous for exposed devices. Successful exploitation could grant an attacker full administrative control over the affected router. The vulnerability has been assigned CVE-2026-51679 and is rated high severity. Proof-of-concept and vendor coordination details have been published on GitHub. TOTOLINK is a network equipment vendor whose devices are widely deployed in home and small business environments.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Related CVE's

  • CVE-2026-51679

IOC's

/cgi-bin/cstecgi.cgi

Categories

  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure