ZeroHour

CVE-2026-51618

moderate

Unauthenticated config disclosure in TOTOLINK T6 router setup wizard

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the getWizardCfg function of its web management CGI. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi on the device's management interface. The result is disclosure of setup wizard and onboarding configuration information; the CVSS score (7.5, AV:N/AC:L/PR:N/UI:N, C:H/I:N/A:N) confirms this is a confidentiality-only issue with no indication of remote code execution. Anyone running the named T6 firmware is affected, with the greatest risk to devices whose management interface is reachable from the internet. No public proof-of-concept is known, the flaw is not in CISA KEV, and its EPSS of 0.4% (30th percentile) suggests exploitation in the next 30 days is unlikely.

What to do: Check whether any TOTOLINK T6 devices on your networks run firmware 4.1.5cu.748_B20211015 and monitor the vendor for a patched release, since no fixed version is identified in the available data. As an interim mitigation, restrict the router's web management interface to the trusted LAN (disable or firewall HTTP/HTTPS management from the WAN) or limit access to /cgi-bin/cstecgi.cgi. Because the flaw only leaks wizard/onboarding configuration, prioritize internet-exposed devices when triaging.

Affected
TOTOLINK T64.1.5cu.748_B20211015
Estimated exposure
moderatelikely on the order of tens of thousands of devices worldwide (single router model with 2021-era firmware) — No public install-base or scan counts exist for this specific model, so this is an estimate from TOTOLINK's budget-router deployment patterns in consumer/SOHO markets and the age of the affected build, which suggests a shrinking installed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.