CVE-2026-51615
largeUnauthenticated information disclosure in TOTOLINK T6 router (getLanCfg)
CVE-2026-51615 is an incorrect access-control flaw (CWE-284) in the getLanCfg function of the web management interface on TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. A remote, unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, which returns the router's LAN addressing and DHCP configuration information without requiring any credentials. The impact is confidentiality-only information disclosure — the attacker learns internal network details but cannot execute code or modify the configuration, reflected in the CVSS 7.5 score with no integrity or availability impact. Only TOTOLINK T6 devices on this firmware build are named as affected, with exposure greatest where the management interface is reachable from the WAN or from untrusted LAN/guest clients. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS places 30-day exploitation probability at about 0.4%, so no exploitation is currently confirmed.
What to do: Inventory TOTOLINK T6 routers and check whether firmware 4.1.5cu.748_B20211015 is installed; no fixed version is specified in the available data, so monitor TOTOLINK advisories for an updated firmware release. Until a patch is available, prevent unauthenticated access to the router's web interface — do not expose /cgi-bin/cstecgi.cgi to the WAN and limit management access to trusted networks — and treat the LAN/DHCP configuration as potentially readable by any unauthenticated client that can reach the device.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (only this build is named in the disclosure; no broader affected version range is provided) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.