VYPR
Published Aug 31, 2026· Updated Sep 1, 2026· 1 source

Totolink T6: 25 Access Control Flaws Disclosed in Single Batch on August 31, 2026

Key findings • 25 vulnerabilities in Totolink T6 firmware (4.1.5cu.748_B20211015) disclosed on August 31, 2026. • All flaws stem from incorrect access control in the /cgi-bin/cstecgi.cgi endp…

Key findings

  • 25 vulnerabilities in Totolink T6 firmware (4.1.5cu.748_B20211015) disclosed on August 31, 2026.
  • All flaws stem from incorrect access control in the /cgi-bin/cstecgi.cgi endpoint, allowing unauthenticated attacks.
  • Vulnerabilities include service termination, device reset, log manipulation, and firmware upload.
  • Three critical vulnerabilities (CVSSv3 9.1) allow removal of Wi-Fi ACLs, clock manipulation, and firewall rule deletion.
  • Affected users should seek official advisories from Totolink for patches and mitigations.

On August 31, 2026, a significant batch of 25 vulnerabilities was disclosed for the Totolink T6 router, all stemming from a single, coordinated disclosure event. These flaws, primarily incorrect access control issues within the /cgi-bin/cstecgi.cgi endpoint, allow unauthenticated attackers to perform a wide range of malicious actions by sending crafted POST requests. The sheer volume and variety of these vulnerabilities highlight a critical security oversight in the T6's firmware, version 4.1.5cu.748_B20211015.

The vulnerabilities can be broadly categorized by the functions they exploit:

System and Configuration Management

Several CVEs target core system functions. CVE-2026-51740 allows attackers to terminate critical services, CVE-2026-51738 enables a full device configuration reset and reboot, and CVE-2026-51737 permits the erasure of traceroute logs. Additionally, CVE-2026-51736 allows for the retrieval of system logs, potentially exposing sensitive information. Attackers can also trigger cloud update checks via CVE-2026-51739 and coordinate mesh slave updates using CVE-2026-51734.

Network and Security Rule Manipulation

A substantial number of vulnerabilities revolve around the manipulation of network security configurations. This includes the removal of Wi-Fi schedule entries (CVE-2026-51732, CVE-2026-51733), VLAN entries (CVE-2026-51731), Wi-Fi ACL rules (CVE-2026-51730), parental control rules (CVE-2026-51726), Smart QoS rules (CVE-2026-51724), URL filtering rules (CVE-2026-51719), static DHCP reservations (CVE-2026-51718), and port-forwarding rules (CVE-2026-51716). Furthermore, attackers can remove firewall filter rules using CVE-2026-51720.

Device and Firmware Control

The batch also includes vulnerabilities related to device control and firmware management. CVE-2026-51729 allows for the deletion of managed slave devices. The ability to upload a crafted firmware image (CVE-2026-51728) and install custom CGI modules (CVE-2026-51723) presents a severe risk, potentially allowing for complete device takeover. Attackers can also change the device's operating mode via CVE-2026-51717, repoint the device to an attacker-controlled upstream Wi-Fi (CVE-2026-51722), and alter the mesh pairing state (CVE-2026-51721).

Critical Impact

Among the disclosed vulnerabilities, three are classified as Critical with a CVSSv3 score of 9.1. CVE-2026-51730 allows for the removal of Wi-Fi ACL rules, CVE-2026-51725 enables attackers to change the device clock, and CVE-2026-51720 permits the removal of firewall filter rules. These critical flaws, alongside the others, grant unauthenticated attackers significant control over the T6 router's functionality and security posture.

The affected firmware version is explicitly stated as 4.1.5cu.748_B20211015. While no specific patch information or updated firmware versions were provided in the disclosure, users are strongly advised to consult Totolink's official security advisories for any available updates or mitigation strategies. The coordinated nature of this disclosure suggests a thorough internal review or external audit may have uncovered these issues.

This extensive set of vulnerabilities underscores the importance of regular firmware updates and security audits for network devices. Users of the Totolink T6 should prioritize investigating their device's security and applying any available patches immediately to prevent potential exploitation. The broad impact of these flaws, ranging from information disclosure to complete device compromise, makes this a critical event for Totolink T6 users. ,cve_ids=[

Synthesized by Vypr AI