Access Control Flaw in TOTOLINK Router Firmware
CVE-2026-51672
9.1CRITICAL
What is CVE-2026-51672?
The TOTOLINK T6 firmware contains an access control vulnerability in the getRoamingCfg function. This flaw allows unauthenticated attackers to exploit the system by sending a specially crafted POST request to the endpoint /cgi-bin/cstecgi.cgi. As a result, attackers can gain access to sensitive information such as the roaming enablement flag, potentially leading to unauthorized changes in network settings and compromised security.
