ZeroHour

CVE-2026-51619

moderate

Unauthenticated Information Disclosure in TOTOLINK T6 Router

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 does not enforce access control on the getOnlineClient function of its web management API, letting anyone query the router's current online client information without logging in. An unauthenticated attacker triggers the flaw by sending a crafted POST request to /cgi-bin/cstecgi.cgi over the network, requiring no credentials or user interaction. The attacker gains read-only visibility into which clients are currently connected to the router (a confidentiality-only issue with no integrity or availability impact), which is useful for reconnaissance or mapping a target network. Affected users are owners of TOTOLINK T6 routers running the listed firmware whose web interface is reachable from untrusted networks, most critically from the internet (WAN). No public proof-of-concept is known, the issue is not listed in CISA KEV, and the 0.4% EPSS score indicates a low near-term probability of exploitation.

What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and whether the web management interface is reachable from the WAN; as an interim mitigation, disable remote management or restrict access to /cgi-bin/cstecgi.cgi to trusted source addresses. No fixed firmware version is identified in current disclosures, so monitor TOTOLINK for an updated release and apply it when published. Given the low EPSS score and absence of a public PoC, there is no evidence of active exploitation, but internet-exposed units should still be locked down.

Affected
TOTOLINK T6 wireless router4.1.5cu.748_B20211015 (firmware; other versions not confirmed in available data)
Estimated exposure
moderatelikely thousands of internet-exposed TOTOLINK T6 routers (order of 1k-10k devices); total installed base unknown — TOTOLINK consumer routers routinely appear in internet-wide scans in the tens of thousands across the brand and the T6 is one of its budget models, so a low-thousands exposed-device figure is a rough extrapolation rather than a published…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.