TOTOLINK T6: 24 Access Control Vulnerabilities Disclosed in Single Batch
Key findings • 24 vulnerabilities in TOTOLINK T6 firmware (4.1.5cu.748_B20211015) disclosed on August 31, 2026. • All flaws stem from incorrect access control in the /cgi-bin/cstecgi.cgi endp…

Key findings
- 24 vulnerabilities in TOTOLINK T6 firmware (4.1.5cu.748_B20211015) disclosed on August 31, 2026.
- All flaws stem from incorrect access control in the /cgi-bin/cstecgi.cgi endpoint, allowing unauthenticated attacks.
- Vulnerabilities impact a wide range of functions including network configuration, access control, and wireless settings.
- Users should seek official advisories from TOTOLINK for patches and mitigations.
On August 31, 2026, a coordinated disclosure event brought to light a significant batch of 24 vulnerabilities affecting the TOTOLINK T6 router, specifically firmware version 4.1.5cu.748_B20211015. All of these flaws share a common root cause: incorrect access control within the SystemSettings function, accessible via the /cgi-bin/cstecgi.cgi endpoint. This allows unauthenticated attackers to manipulate various router settings and functionalities through crafted POST requests.
The vulnerabilities can be broadly categorized by the specific functions they impact:
Configuration Management
A large number of CVEs allow attackers to alter critical device configurations. This includes changing the device operating mode (CVE-2026-51717), manipulating WAN dial state (CVE-2026-51713), reconfiguring primary Wi-Fi settings (CVE-2026-51709), and altering IPTV service configurations (CVE-2026-51697).
Network and Access Control
Several vulnerabilities focus on manipulating network access and security rules. Attackers can remove URL filtering rules (CVE-2026-51719), delete static DHCP reservations (CVE-2026-51718), remove MAC filter rules (CVE-2026-51715), alter firewall policies (CVE-2026-51702), and change device access control (CVE-2026-51701). Additionally, attackers can expose internal services by manipulating port forwarding rules (CVE-2026-51696, CVE-2026-51716) and expose an internal host via the DMZ configuration (CVE-2026-51699).
Wireless Settings
The wireless functionality of the TOTOLINK T6 is also heavily impacted. Attackers can alter roaming behavior (CVE-2026-51714), change WPS availability (CVE-2026-51708), rename mesh entries (CVE-2026-51705), alter mesh configurations (CVE-2026-51704), and degrade wireless behavior (CVE-2026-51700). Furthermore, attackers can create or weaken guest wireless access (CVE-2026-51687) and alter when Wi-Fi is available (CVE-2026-51703).
Other Functionality
Beyond configuration and access control, other functions are also vulnerable. Attackers can retrieve administrative import and export endpoint information (CVE-2026-51727), degrade traffic handling through QoS settings (CVE-2026-51706), and open a wireless pairing window (CVE-2026-51711).
The Vypr Intelligence report highlights that three critical vulnerabilities (CVSSv3 9.1) allow for the removal of Wi-Fi ACLs, clock manipulation, and firewall rule deletion. While the provided CVE details do not explicitly state which specific CVEs correspond to these critical impacts, the common theme of unauthenticated manipulation of sensitive settings is evident across all disclosed vulnerabilities.
Users of the TOTOLINK T6 router with firmware version 4.1.5cu.748_B20211015 are strongly advised to seek official advisories from TOTOLINK for available patches and mitigations. Given the nature and volume of these vulnerabilities, prompt action is recommended to secure affected devices against potential unauthenticated access and configuration manipulation. The tight disclosure window suggests a single, coordinated effort to reveal these security weaknesses.