Access Control Flaw in TOTOLINK Router Product
CVE-2026-51742
5.9MEDIUM
What is CVE-2026-51742?
A flaw in the discoverWan function of the TOTOLINK T6 allows unauthenticated attackers to exploit incorrect access controls. By sending a specially crafted POST request to /cgi-bin/cstecgi.cgi, an attacker can trigger WAN discovery functionalities, potentially leading to further attacks on the network infrastructure. This vulnerability highlights the importance of robust access control mechanisms in network devices to prevent unauthorized interactions.
