ZeroHour

CVE-2026-51616

moderate

Unauthenticated information disclosure in TOTOLINK T6 router getWanIeCfg

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the getWanIeCfg function of its web API. An unauthenticated remote attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and retrieve the router's LAN addressing and DHCP configuration information without any credentials. The disclosed data exposes internal network layout and DHCP settings, which is primarily useful for reconnaissance ahead of further attacks rather than granting direct control of the device. Only TOTOLINK T6 units running the named firmware build are documented as affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and the EPSS score of 0.4% (30th percentile) indicates a low near-term exploitation probability.

What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and, since no fixed version is specified in the available data, watch for a corrected release from TOTOLINK and update when published. Until then, disable or firewall WAN-side access to the router's management interface and restrict /cgi-bin/cstecgi.cgi to trusted networks. Because the leak only exposes LAN/DHCP details, prioritize it as a reconnaissance hardening item rather than an urgent compromise risk.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (only build named in the advisory; other builds not confirmed)
Estimated exposure
moderatelikely on the order of thousands of internet-exposed T6 devices (rough estimate; per-model counts unpublished) — TOTOLINK SOHO routers are commonly found with their web management interface exposed to the internet in public scans and this firmware build appears across multiple TOTOLINK advisories suggesting broad shipment, but no published…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.