Summary
CVE-2026-51692 is an incorrect access control vulnerability in the setWiFiGuestCfg function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to establish or weaken guest wireless network access via a crafted POST request, and it carries a CRITICAL severity rating.
Technical details
- Root cause: the
setWiFiGuestCfgfunction, exposed through the device’s CGI handler, does not enforce authentication or authorization checks before processing configuration changes. - Trigger condition: an attacker sends a crafted HTTP POST request to
/cgi-bin/cstecgi.cgiinvoking thesetWiFiGuestCfgaction. - Attack vector: network-based, no authentication or user interaction required, low attack complexity.
- Impact: attackers can enable, disable, or weaken guest Wi-Fi network settings on the router without credentials, potentially exposing the device and connected network segments to unauthorized wireless access.
Affected software
- TOTOLINK T6, firmware version 4.1.5cu.748_B20211015
Severity
- CVSS v3.1 Base Score: 9.1 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: check the TOTOLINK support site for a firmware build newer than 4.1.5cu.748_B20211015 for the T6 model and apply it; at the time of publication no vendor-confirmed fixed version was identified.
- If no patch is available: restrict management/administrative interfaces (including
/cgi-bin/cstecgi.cgi) from being reachable over the internet, place the device behind a firewall or VPN, disable remote management, and monitor for unexpected changes to guest Wi-Fi configuration.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/cgi-bin/cstecgi.cgi - Page title:
TOTOLINK

