External risk intelligence

TOTOLINK T6 Wi-Fi Schedule Removal Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51733

The vulnerability exists in the web management interface of a network router. These interfaces are commonly exposed to the local network and, in many residential or small office deployments, are inadvertently or intentionally exposed to the public internet, making them reachable for external requests to the CGI gateway.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical security flaw found in the firmware of TOTOLINK T6 routers, specifically within its Wi-Fi scheduling function. An unauthenticated attacker could exploit this vulnerability to remove Wi-Fi schedule entries, potentially disrupting network operations. The main concern at this time is confirming whether this specific technology is in use and thus potentially exposed.

  • Unauthenticated attackers can disable Wi-Fi schedules.
  • Disrupts network operations; affects specific router models.
  • Confirm relevance and exposure of affected devices.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can initiate an attack from the internet by sending a specially crafted request to the router's web interface. This request targets the Firmware Upgrade function, exploiting an access control weakness to manipulate Wi-Fi schedule settings. Successful exploitation could allow an attacker to disable or alter the Wi-Fi schedule.

  • No authentication is required.
  • Triggered by sending a POST request.
  • Allows modification of Wi-Fi schedules.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could remove Wi-Fi schedule entries on affected devices by sending a specially crafted request. This could disrupt normal network operations.

  • Wi-Fi schedule configurations could be affected.
  • Attackers may send POST requests to the device.
  • Wi-Fi availability could be interrupted.

Operational Fix

Recommended remediation, mitigation, and detection steps

Infrastructure and network teams are likely responsible for managing TOTOLINK T6 routers. The first practical step is to identify all deployed T6 routers, determine their network exposure (internal or external), confirm business criticality, and then assign ownership for remediation planning.

  • Infrastructure or network teams own the issue.
  • Verify router exposure and criticality first.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6 and what is it used for?

The TOTOLINK T6 is a network router designed for residential or small office environments. It acts as a central hub for managing internet connectivity and Wi-Fi access for connected devices, providing a web-based management interface for users to configure network settings like Wi-Fi schedules.

What does the CVE-2026-51733 vulnerability mean?

This vulnerability is classified as Improper Access Control (CWE-284). It means the router fails to properly check if a user has permission to perform certain actions. Specifically, it allows anyone, even without logging in, to access a function meant for firmware management and use it to delete existing Wi-Fi schedule settings.

How is this vulnerability triggered by an attacker?

An attacker triggers this bug by sending a specially crafted POST request to the router's CGI gateway. It is important to note that the vulnerability does not require the attacker to have a valid username or password to be successful; the device incorrectly accepts these unauthorized requests as if they were legitimate commands.

Why should I be concerned about CVE-2026-51733?

According to Halo Surface Signal, this vulnerability is risky because it resides in the web management interface of a network router. While these are typically meant for the local network, they are often accidentally or intentionally exposed to the public internet, making the device reachable by external actors who could disrupt your network connectivity.

Do I need to take immediate action if I use this router?

Your first step is to perform an inventory of your environment to identify any TOTOLINK T6 routers in use. Once identified, confirm if these devices are accessible from the internet or restricted to your internal network to understand your risk, then coordinate with your infrastructure team to plan for remediation.

References