ZeroHour

CVE-2026-51621

large

Unauthenticated configuration disclosure in TOTOLINK T6 router (getInitCfg)

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51621 is an improper access control flaw (CWE-284) in the getInitCfg function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015, which serves sensitive device configuration data without requiring authentication. An unauthenticated attacker triggers it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint. The impact is confidentiality-only per the CVSS vector (no integrity or availability loss), but the exposed configuration details could aid follow-on attacks against the device or network. Affected parties are operators of TOTOLINK T6 routers running the listed firmware build; other firmware versions have not been confirmed as vulnerable in the available data. No public proof-of-concept, KEV listing, or confirmed exploitation exists so far, and EPSS places the 30-day exploitation probability at roughly 0.4%.

What to do: Check TOTOLINK's official support/download page for a T6 firmware build newer than 4.1.5cu.748_B20211015 and upgrade, since no fixed version is identified in the available data. In the meantime, disable WAN-side remote management and restrict access to /cgi-bin/cstecgi.cgi to trusted LAN clients with firewall/ACL rules, and review web logs for unauthenticated POST requests invoking getInitCfg.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (only build cited; other versions unverified)
Estimated exposure
large≈10,000–100,000 internet-exposed T6 routers (estimate) — TOTOLINK budget/consumer routers routinely appear in public internet-wide scans at the tens-of-thousands level across the vendor's model range and the T6 is one of its common entry-level models, but no per-model exposed-device count is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.