ZeroHour

CVE-2026-51617

Unauthenticated Information Disclosure in TOTOLINK T6 Router (getSysStatusCfg)

CVSS 3.1
7.5 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-51617 is an improper access control flaw (CWE-284) in the getSysStatusCfg handler of the web management API on TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015, which fails to require authentication for a sensitive status endpoint. An unauthenticated attacker triggers it by sending a crafted POST request to /cgi-bin/cstecgi.cgi that invokes getSysStatusCfg. The response leaks the device's operation mode, firmware version, serial number, WAN and LAN IP addresses, WiFi SSID, wireless encryption keys, and connected-client statistics, information that can enable follow-on attacks such as joining the wireless network or mapping the LAN. Only TOTOLINK T6 routers on the cited firmware are affected, and exposure is greatest where the router's management interface is reachable from the internet. There is no public PoC, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at just 0.3%, so no active exploitation is currently known.

What to do: Determine whether your T6's management interface is reachable from the WAN; if so, disable remote management or restrict it to trusted management networks until a vendor fix is available, since no patched firmware version is documented in the available data. Check the running firmware version and watch TOTOLINK's advisories for an updated release addressing CVE-2026-51617.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the firmware version cited in the report; no other ranges confirmed)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, encryption keys, and connected client statistics via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.