Summary
CVE-2026-51690 is an improper access control vulnerability in the setWanCfg function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. It allows an unauthenticated, remote attacker to send a crafted POST request to the device’s CGI handler and alter the router’s upstream (WAN) provisioning and connectivity settings. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).
Technical details
- Root cause: The
setWanCfgfunction, exposed through the/cgi-bin/cstecgi.cgibinary, does not enforce authentication or session validation before processing WAN configuration change requests. - Trigger conditions: An attacker sends a specially crafted HTTP POST request targeting the
setWanCfgaction on/cgi-bin/cstecgi.cgi, with no prior login or valid session required. - Attack vector: Network — the vulnerable CGI endpoint is reachable over the router’s exposed HTTP management interface without authentication.
- Impact: Unauthenticated modification of upstream provisioning and connectivity settings, which can be used to disrupt internet connectivity, redirect traffic, or otherwise manipulate WAN-side network behavior. The published CVSS vector indicates high confidentiality and integrity impact with no availability impact.
Affected software
- TOTOLINK T6, firmware version 4.1.5cu.748_B20211015
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- No vendor patch has currently been identified for this specific firmware version; consult TOTOLINK’s official support/download channels for updated firmware for the T6 model and apply it as soon as it becomes available.
- Until a patch is released, restrict access to the router’s management/CGI interface (
/cgi-bin/cstecgi.cgi) — disable remote/WAN-side management, disable UPnP, and limit administrative access to trusted internal networks only. - Place affected devices behind a firewall or VPN so the management interface is not directly reachable from the internet.
- Monitor for unexpected changes to WAN/provisioning settings and consider replacing or isolating end-of-life TOTOLINK devices that no longer receive security updates.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/cgi-bin/cstecgi.cgi - Page title:
TOTOLINK

