Sceawere

Vulnerability Detail

CVE-2026-51700UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Improper Access Control

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-31T16:18:35.143Z",
  "pubdate": "2026-08-31T16:18:35.143Z",
  "executiveSummary": "A critical vulnerability exists in the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015, categorized as improper access control within the device's management interface.\nThis security flaw allows unauthenticated remote attackers to interact with internal administrative functions without prior validation of session credentials.\nThe vulnerability resides specifically within the setWiFiAdvancedCfg function, which is exposed via the /cgi-bin/cstecgi.cgi endpoint.\nSuccessful exploitation enables an attacker to manipulate wireless configuration settings, leading to the intentional degradation of wireless network performance or connectivity.\nThe risk is categorized as high due to the lack of required authentication, allowing any network-adjacent attacker to perform unauthorized administrative actions against the device's wireless subsystem.\nThis issue exposes the device to denial-of-service conditions or malicious configuration changes that could disrupt legitimate user access.",
  "technicalDetails": "The vulnerability is rooted in a failure to enforce authorization checks within the setWiFiAdvancedCfg function, which processes configuration commands for the TOTOLINK T6 wireless subsystem.\nThe CGI interface located at /cgi-bin/cstecgi.cgi acts as the primary gateway for system management, yet it fails to verify the identity of the requester before dispatching commands to the underlying function.\nThe attack flow begins when an unauthenticated attacker transmits a crafted POST request to the target device's /cgi-bin/cstecgi.cgi endpoint.\nBy manipulating the request body to target the setWiFiAdvancedCfg function, the attacker can supply arbitrary parameters intended for the wireless configuration management logic.\nBecause the function does not validate the authentication state of the session or the privilege level of the user, the firmware executes the provided parameters with elevated administrative authority.\nThis lack of access control allows the attacker to rewrite critical wireless parameters, such as beacon intervals, channel bandwidth, or SSID broadcast settings, effectively degrading the device's wireless performance or causing service instability.\nThe exploitation occurs entirely over the network, requiring only reachability to the web-based management interface of the affected T6 hardware.\nThe payload behaves by directly interacting with the binary's internal logic, bypassing the standard web UI authentication middleware that typically gates access to administrative configuration modules.\nBecause this function is exposed to unauthenticated input, it represents a significant security oversight in the firmware's design, effectively converting a restricted internal management function into a publicly accessible command injection point for configuration parameters.\nThe impact of this exploit is not limited to simple configuration changes; it potentially facilitates a total compromise of the wireless communication channel, permitting further reconnaissance or persistent disruptions of network traffic flow."
}
CVE-2026-51700: TOTOLINK T6 Improper Access Control (CRITICAL Severity, CVSS: 9.1) - Sceawere