CVE-2026-51620
moderateUnauthenticated information disclosure in TOTOLINK T6 router firmware
CVE-2026-51620 is an improper access control flaw (CWE-284) in the getNetInfoCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated remote attacker can trigger it by sending a crafted POST request to the router's management endpoint /cgi-bin/cstecgi.cgi. The impact is limited to information disclosure: the attacker can read network topology and interface configuration details, with no indication of code execution or modification of device settings (CVSS 3.1: 7.5, confidentiality-only). Owners of TOTOLINK T6 routers running the affected firmware are exposed, particularly when the management interface is reachable from the WAN or untrusted networks. As of now there is no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days, so no active exploitation is known.
What to do: Check whether T6 units you manage run firmware 4.1.5cu.748_B20211015 and watch TOTOLINK's support site for a corrected firmware release, as no fixed version is specified in the current data. In the meantime, restrict access to the router's management interface (disable remote/WAN administration, limit access to trusted management networks, or firewall /cgi-bin/cstecgi.cgi), since the attack requires no authentication. Because the leak exposes network topology and interface configuration, treat any exposed unit as having revealed internal network details and review whether that information could enable follow-on attacks.
| TOTOLINK T6 (wireless router) | 4.1.5cu.748_B20211015 (firmware version cited in the advisory; whether other firmware versions are affected is unspecified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.