Access Control Flaw in TOTOLINK Router Allows Unauthorized Language Configuration Changes
CVE-2026-51668
7.5HIGH
What is CVE-2026-51668?
In the TOTOLINK T6 Router version 4.1.5cu.748_B20211015, a vulnerability exists within the setLanguageCfg function that enables unauthenticated users to manipulate language settings. This flaw is exploited by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint, potentially allowing attackers to alter critical configurations without proper authorization, thereby compromising the device's intended operations.
