ZeroHour

CVE-2026-51615

large

Unauthenticated information disclosure in TOTOLINK T6 router (getLanCfg)

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51615 is an incorrect access-control flaw (CWE-284) in the getLanCfg function of the web management interface on TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. A remote, unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, which returns the router's LAN addressing and DHCP configuration information without requiring any credentials. The impact is confidentiality-only information disclosure — the attacker learns internal network details but cannot execute code or modify the configuration, reflected in the CVSS 7.5 score with no integrity or availability impact. Only TOTOLINK T6 devices on this firmware build are named as affected, with exposure greatest where the management interface is reachable from the WAN or from untrusted LAN/guest clients. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS places 30-day exploitation probability at about 0.4%, so no exploitation is currently confirmed.

What to do: Inventory TOTOLINK T6 routers and check whether firmware 4.1.5cu.748_B20211015 is installed; no fixed version is specified in the available data, so monitor TOTOLINK advisories for an updated firmware release. Until a patch is available, prevent unauthenticated access to the router's web interface — do not expose /cgi-bin/cstecgi.cgi to the WAN and limit management access to trusted networks — and treat the LAN/DHCP configuration as potentially readable by any unauthenticated client that can reach the device.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (only this build is named in the disclosure; no broader affected version range is provided)
Estimated exposure
largeplausibly tens of thousands of T6 devices (exact install base unknown) — No install counts were provided, so the estimate is based on TOTOLINK's wide deployment as a budget SOHO/consumer router brand and public internet scans (Shodan/Censys) showing tens of thousands of TOTOLINK devices exposing the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.