


Perceptive Security
SOC/SIEM Consultancy

Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a cr…
Published:
31 augustus 2026 om 00:00:00
Alert date:
31 augustus 2026 om 23:17:03
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
CVE-2026-51680 is an incorrect access control vulnerability discovered in the setLedCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to modify the device's LED behavior by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication or credentials are required to exploit this vulnerability, making it trivially accessible to any attacker with network access to the device. The vulnerability stems from insufficient access controls on a CGI-based web interface function. TOTOLINK T6 is a consumer/SOHO network router, meaning exploitation could affect home and small business environments. Proof-of-concept and vendor coordination details have been published on GitHub by security researchers. The vendor's official website and firmware download pages have been referenced as part of the disclosure.
Technical details
Mitigation steps:
Affected products:
TOTOLINK T6 4.1.5cu.748_B20211015
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51680
https://github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
https://github.com/ShengWu00/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
https://www.totolink.net/
https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
