External risk intelligence

TOTOLINK T6 Wi-Fi Repeater Unauthorized Upstream Network Redirection

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-51722

The vulnerability exists in a Wi-Fi repeater device, which is network-based hardware. Devices of this type are commonly deployed as edge-facing components or gateways that connect internal networks to external upstream networks, making their management interfaces or configuration endpoints often accessible from the network they serve.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical security vulnerability found in TOTOLINK Wi-Fi repeater devices. The issue allows unauthorized attackers to remotely redirect the device to a network controlled by the attacker, potentially impacting the integrity and confidentiality of network traffic. The primary concern is confirming if these devices are deployed within the organization's environment.

  • Attackers can redirect Wi-Fi repeaters.
  • This could compromise network traffic access.
  • Confirm device relevance and exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can target a Wi-Fi repeater device by sending a specially crafted request over the network. This request targets a specific function that handles the device's configuration, allowing the attacker to redirect the device's connection to an upstream Wi-Fi network they control.

  • Network access required, no authentication.
  • Triggered by sending a crafted POST request.
  • Reroutes device to attacker-controlled network.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to redirect a device's network traffic to a network they control, potentially affecting its upstream internet connectivity. This is possible when the device is accessible via a network interface and an attacker can send a specially crafted request.

  • Device's network traffic.
  • Via crafted POST request.
  • Unauthenticated network redirection.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world responsibility for this vulnerability likely falls to the infrastructure or network operations teams who manage edge devices and the security team responsible for network perimeter defense. The initial practical step involves identifying all deployed TOTOLINK T6 devices, verifying their network exposure, confirming business criticality, and then assigning an owner for remediation planning.

  • Infrastructure and security teams own triage.
  • Verify device network exposure and criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6?

The TOTOLINK T6 is a Wi-Fi repeater designed to extend the range of wireless networks. Users deploy these devices to bridge signal gaps in their environment by connecting to an upstream Wi-Fi source and rebroadcasting it. Because they act as a bridge between your local devices and the internet, they serve as critical infrastructure nodes that manage how and where your network traffic flows.

What is the security weakness in CVE-2026-51722?

This vulnerability is classified as CWE-284, which refers to improper access control. In plain terms, the device fails to verify if a user is authorized before allowing them to change sensitive system settings. Specifically, the setWiFiRepeaterCfg function does not check for authentication, allowing anyone who can reach the device to modify its connection parameters.

How is this vulnerability triggered?

An attacker triggers the flaw by sending a specifically crafted POST request to the device's web interface at the /cgi-bin/cstecgi.cgi endpoint. The request does not require any login credentials to succeed. It is important to note that simply visiting the device's web page or normal browsing will not trigger this; the attacker must intentionally submit the specific malicious configuration command.

Is my TOTOLINK T6 at risk?

If you use this device, you should assess its reachability. According to Halo Surface Signal, because this is a network-based hardware device, it is often deployed as a gateway or edge component. If your device's management interface is accessible from a network that an unauthorized party can reach, it may be at risk of being redirected to an attacker-controlled network.

What should I do to address this issue?

The first step is to locate all TOTOLINK T6 units currently in use across your infrastructure. Once identified, determine if these devices are exposed to untrusted networks. After confirming their location and business criticality, coordinate with your network or infrastructure team to restrict access to the device's management interface and prepare for remediation as vendor updates become available.

References