CVE-2026-51616
moderateUnauthenticated information disclosure in TOTOLINK T6 router getWanIeCfg
TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the getWanIeCfg function of its web API. An unauthenticated remote attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and retrieve the router's LAN addressing and DHCP configuration information without any credentials. The disclosed data exposes internal network layout and DHCP settings, which is primarily useful for reconnaissance ahead of further attacks rather than granting direct control of the device. Only TOTOLINK T6 units running the named firmware build are documented as affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and the EPSS score of 0.4% (30th percentile) indicates a low near-term exploitation probability.
What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and, since no fixed version is specified in the available data, watch for a corrected release from TOTOLINK and update when published. Until then, disable or firewall WAN-side access to the router's management interface and restrict /cgi-bin/cstecgi.cgi to trusted networks. Because the leak only exposes LAN/DHCP details, prioritize it as a reconnaissance hardening item rather than an urgent compromise risk.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (only build named in the advisory; other builds not confirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.