


Perceptive Security
SOC/SIEM Consultancy

Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration vi…
Published:
31 August 2026 at 00:00:00
Alert date:
31 August 2026 at 23:17:03
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Identity & Access
CVE-2026-51681 describes an incorrect access control vulnerability in the setRemoteCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to expose WAN-side administration interfaces by sending a crafted HTTP POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication is required to exploit this vulnerability, making it particularly dangerous for internet-facing devices. The affected product is a consumer/SOHO router manufactured by TOTOLINK. Successful exploitation could allow attackers to enable or reconfigure remote management settings without authorization. This type of vulnerability is common in IoT and home networking equipment where firmware access controls are improperly implemented. References include GitHub-hosted vendor coordination disclosures and the official TOTOLINK website and firmware download page.
Technical details
Mitigation steps:
Affected products:
TOTOLINK T6 4.1.5cu.748_B20211015
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51681
https://github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
https://github.com/ShengWu00/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
https://www.totolink.net/
https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
