Description
Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized configuration of the device’s upstream Wi‑Fi network
Action: Assess Impact
AI Analysis

Impact

The vulnerability lies in improper access control within the setWiFiRepeaterCfg function, allowing an unauthenticated attacker to repoint a TOTOLINK T6 device to an attacker‑controlled upstream Wi‑Fi by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This weakness is a Classic Incorrect Access Control flaw (CWE‑284), which can lead to unauthorized network configuration changes, potential loss of connectivity, and the device acting as an untrusted point of access to external networks.

Affected Systems

Affected are TOTOLINK T6 wireless repeaters running firmware version 4.1.5cu.748_B20211015. No other vendors or product versions are listed as impacted by the issue.

Risk and Exploitability

Because the flaw allows unauthenticated modification of the upstream Wi‑Fi settings, an attacker only needs network reachability to the device’s management interface. The EPSS score is < 1% and the issue is not listed in KEV, suggesting no publicly available exploit at the time of analysis, but the lack of authentication means a successful exploitation is trivially feasible if the attacker can reach the target. The CVSS score of 9.1 indicates critical severity.

Generated by OpenCVE AI on September 2, 2026 at 04:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the device firmware version and apply any available vendor patch that removes the unauthenticated configuration capability.
  • Restrict external access to the device’s control interface by firewalling or blocking POST requests to /cgi-bin/cstecgi.cgi from untrusted networks.
  • Segregate the device on a separate VLAN or network segment and monitor configuration changes for anomalies.

Generated by OpenCVE AI on September 2, 2026 at 04:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Upstream Wi‑Fi Reconfiguration via POST Request in TOTOLINK T6

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Mon, 31 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Upstream Wi‑Fi Reconfiguration via POST Request in TOTOLINK T6
Weaknesses CWE-284

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T15:08:15.144Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51722

cve-icon Vulnrichment

Updated: 2026-09-01T15:07:03.412Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T17:17:41.730

Modified: 2026-09-01T15:17:18.160

Link: CVE-2026-51722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:45:17Z

Weaknesses