top of page
perceptive_background_267k.jpg

Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a cr…

Published:

31 augustus 2026 om 00:00:00

Alert date:

31 augustus 2026 om 23:17:03

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure

CVE-2026-51680 is an incorrect access control vulnerability discovered in the setLedCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to modify the device's LED behavior by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication or credentials are required to exploit this vulnerability, making it trivially accessible to any attacker with network access to the device. The vulnerability stems from insufficient access controls on a CGI-based web interface function. TOTOLINK T6 is a consumer/SOHO network router, meaning exploitation could affect home and small business environments. Proof-of-concept and vendor coordination details have been published on GitHub by security researchers. The vendor's official website and firmware download pages have been referenced as part of the disclosure.

Technical details

Mitigation steps:

Affected products:

TOTOLINK T6 4.1.5cu.748_B20211015

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page