← Terug naar overzicht

A critical incorrect access control vulnerability exists in the setPasswordCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to change the administrator account credentials without any prior authentication. Exploitation is achieved by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. This effectively grants full administrative control of the affected router to an attacker. The vulnerability has been documented by multiple researchers and coordinated with the vendor. TOTOLINK T6 is a consumer/SOHO network router, making this vulnerability particularly impactful for home and small business users. No authentication or special privileges are required to exploit this flaw. The issue represents a severe security risk as it enables complete device takeover.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Related CVE's

  • CVE-2026-51679

Categories

  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure