Access Control Flaw in TOTOLINK Router Product
CVE-2026-51742

5.9MEDIUM

Key Information:

Vendor

TOTOLINK

Vendor
CVE Published:
1 September 2026

What is CVE-2026-51742?

A flaw in the discoverWan function of the TOTOLINK T6 allows unauthenticated attackers to exploit incorrect access controls. By sending a specially crafted POST request to /cgi-bin/cstecgi.cgi, an attacker can trigger WAN discovery functionalities, potentially leading to further attacks on the network infrastructure. This vulnerability highlights the importance of robust access control mechanisms in network devices to prevent unauthorized interactions.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.