Totolink · Totolink T6 · CVE-2026-51688
**Name of the Vulnerable Software and Affected Versions**
TOTOLINK T6 version 4.1.5cu.748 B20211015
**Description**
Incorrect access control in the `setWiFiSignalCfg()` function allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS), which is a condition where the service becomes unavailable to its intended users. This is achieved by sending a crafted POST request to the '/cgi-bin/cstecgi.cgi' endpoint.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.