CVE-2026-51618
moderateUnauthenticated config disclosure in TOTOLINK T6 router setup wizard
TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the getWizardCfg function of its web management CGI. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi on the device's management interface. The result is disclosure of setup wizard and onboarding configuration information; the CVSS score (7.5, AV:N/AC:L/PR:N/UI:N, C:H/I:N/A:N) confirms this is a confidentiality-only issue with no indication of remote code execution. Anyone running the named T6 firmware is affected, with the greatest risk to devices whose management interface is reachable from the internet. No public proof-of-concept is known, the flaw is not in CISA KEV, and its EPSS of 0.4% (30th percentile) suggests exploitation in the next 30 days is unlikely.
What to do: Check whether any TOTOLINK T6 devices on your networks run firmware 4.1.5cu.748_B20211015 and monitor the vendor for a patched release, since no fixed version is identified in the available data. As an interim mitigation, restrict the router's web management interface to the trusted LAN (disable or firewall HTTP/HTTPS management from the WAN) or limit access to /cgi-bin/cstecgi.cgi. Because the flaw only leaks wizard/onboarding configuration, prioritize internet-exposed devices when triaging.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.