CVE-2026-51622
moderateUnauthenticated access-control flaw in TOTOLINK T6 router exposes WAN config
CVE-2026-51622 is an incorrect access-control issue (CWE-284) in the getWanCfg function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated remote attacker triggers the flaw by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi CGI endpoint, which handles the getWanCfg request without enforcing authentication. A successful request returns the device's WAN configuration data, giving the attacker visibility into sensitive connectivity settings (the published CVSS 3.1 vector scores high confidentiality and integrity impact). Any T6 unit running the listed firmware is affected, and because the request requires no credentials or user interaction, any device that exposes this CGI endpoint over the network is at risk. There is currently no evidence of exploitation: the flaw is not in CISA's KEV, no public PoC is known, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.
What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 via the admin UI and apply TOTOLINK's fixed firmware when the vendor publishes one (no fixed version is named in the advisory). Until then, keep the web management interface — including /cgi-bin/cstecgi.cgi — reachable only from the LAN and never forwarded or exposed to the WAN, since the flaw requires no authentication. No public PoC or in-the-wild exploitation is known, but watch the vendor's support page for an updated release.
| TOTOLINK T6 router | Firmware 4.1.5cu.748_B20211015 (the only version named in the advisory; other firmware versions are not confirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.