Summary
CVE-2026-51733 is an incorrect access control vulnerability in the FirmwareUpgrade function of the TOTOLINK T6 wireless router, firmware 4.1.5cu.748_B20211015. It allows a remote, unauthenticated attacker to send a crafted HTTP POST request to the device’s management CGI interface and remove Wi-Fi schedule entries without any credentials. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: the
FirmwareUpgradehandler within/cgi-bin/cstecgi.cgifails to enforce authentication/authorization checks before processing requests that modify device configuration. - Trigger condition: an attacker sends a specially crafted POST request to
/cgi-bin/cstecgi.cgitargeting the vulnerable function. - Attack vector: network-based, no user interaction and no privileges required.
- Impact: unauthorized removal of Wi-Fi schedule entries, indicating broader improper access control on the management interface; CVSS impact metrics rate confidentiality, integrity, and availability impact as High.
- This CVE is one of several similarly-structured incorrect access control findings disclosed for the same TOTOLINK T6 firmware build and CGI endpoint.
Affected software
- TOTOLINK T6, firmware version 4.1.5cu.748_B20211015
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No official TOTOLINK patch has been confirmed for this specific firmware build at time of writing; check the TOTOLINK support/download portal for an updated firmware release for the T6 model and apply it as soon as it becomes available.
- If no patch: Restrict network access to the router’s management interface (
/cgi-bin/cstecgi.cgi) so it is not reachable from the public internet; disable remote/WAN administration; place the device behind a firewall or VPN limiting access to trusted management networks; monitor for unexpected configuration changes such as removed Wi-Fi schedules.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/cgi-bin/cstecgi.cgi - Page title:
TOTOLINK

