External risk intelligence

TOTOLINK T6 Router WAN Dial Manipulation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-51713

The vulnerability exists in a home/small office router product and allows unauthenticated manipulation of WAN dial settings via a web interface. Such devices are designed to be internet-facing by default, and the exposed management endpoint is reachable over the network to facilitate standard router configuration and WAN connectivity.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical security vulnerability in TOTOLINK routers. The issue involves improper access controls that could allow an unauthenticated attacker to alter the device's internet connection status by sending a specially crafted request. This could potentially disrupt network services or be used as part of a larger attack chain.

  • Attackers can change router internet settings.
  • Internet-facing devices are often targeted.
  • Confirm if your network uses affected devices.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request to the router's web interface. This request targets the setManualDialCfg function, which lacks proper access controls. By successfully triggering this function, an attacker could manipulate the Wide Area Network (WAN) dial state.

  • Network accessible, no authentication needed.
  • Manipulate WAN dial settings via POST request.
  • Unauthorized control over network connectivity.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker can manipulate the Wide Area Network (WAN) dial state of a TOTOLINK T6 router when it is exposed to the network. This manipulation could potentially affect internet connectivity and the router's ability to establish or maintain a connection.

  • WAN dial state.
  • Crafted POST request to the router.
  • Interruption of internet service.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in TOTOLINK routers is likely the responsibility of the network infrastructure or platform team, given its impact on device configuration and network access. The first step is to identify all deployed TOTOLINK routers, assess their internet exposure and criticality, and then coordinate with the vendor for a fix or implement temporary mitigation if direct patching is not immediately feasible.

  • Network infrastructure teams own remediation.
  • Verify internet-facing router exposure.
  • Plan vendor coordination or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6 router?

The TOTOLINK T6 is a networking device typically used in homes or small offices to manage internet connectivity. It functions as a router, directing traffic between the Wide Area Network (WAN), which connects to your service provider, and your local devices. Because it manages network entry points, it includes an administrative interface that allows users to configure settings like dial-up connections and connection states.

What does CWE-284 mean for CVE-2026-51713?

CWE-284 refers to Improper Access Control. In the context of this vulnerability, it means the router's software fails to properly verify the identity of the person attempting to change settings. Specifically, the function responsible for managing WAN dial configurations does not enforce security checks, allowing unauthorized commands to be executed as if they were requested by a trusted administrator.

How is this vulnerability triggered?

An attacker triggers this bug by sending a specific, crafted POST request to the router's web management interface at /cgi-bin/cstecgi.cgi. This request targets the setManualDialCfg function. The vulnerability is triggered solely by this network request; it does not require an attacker to have a password, physical access, or valid user credentials to modify the WAN dial state.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates that because the TOTOLINK T6 is designed as a router, its management interface is often reachable over the network by default. Since the vulnerability allows unauthenticated access, any device that is internet-facing—meaning it can be reached directly from outside your private network—is at a much higher risk of having its WAN connectivity manipulated.

How should I respond to this advisory?

First, inventory your network to identify if any TOTOLINK T6 units are in use. Check if these devices are exposed directly to the internet. If you find affected hardware, prioritize restricting access to the management interface. Contact the manufacturer to verify if a firmware update is available to resolve the access control deficiency, and ensure your devices are running the latest software provided by the vendor.

References