ZeroHour

CVE-2026-51622

moderate

Unauthenticated access-control flaw in TOTOLINK T6 router exposes WAN config

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51622 is an incorrect access-control issue (CWE-284) in the getWanCfg function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated remote attacker triggers the flaw by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi CGI endpoint, which handles the getWanCfg request without enforcing authentication. A successful request returns the device's WAN configuration data, giving the attacker visibility into sensitive connectivity settings (the published CVSS 3.1 vector scores high confidentiality and integrity impact). Any T6 unit running the listed firmware is affected, and because the request requires no credentials or user interaction, any device that exposes this CGI endpoint over the network is at risk. There is currently no evidence of exploitation: the flaw is not in CISA's KEV, no public PoC is known, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.

What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 via the admin UI and apply TOTOLINK's fixed firmware when the vendor publishes one (no fixed version is named in the advisory). Until then, keep the web management interface — including /cgi-bin/cstecgi.cgi — reachable only from the LAN and never forwarded or exposed to the WAN, since the flaw requires no authentication. No public PoC or in-the-wild exploitation is known, but watch the vendor's support page for an updated release.

Affected
TOTOLINK T6 routerFirmware 4.1.5cu.748_B20211015 (the only version named in the advisory; other firmware versions are not confirmed)
Estimated exposure
moderate≈1,000–10,000 internet-exposed T6 units (tens of thousands of TOTOLINK routers appear in public internet-wide scans across the vendor's catalog; T6-specific… — No per-model scan or sales counts were provided in the data; TOTOLINK consumer/SOHO routers are regularly indexed by internet-wide scans in the thousands, and the T6 is a single model on one listed firmware, so exposed units plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.