CVE-2026-51624
Unauthenticated client MAC disclosure in TOTOLINK T6 router firmware
CVE-2026-51624 is an improper access-control flaw (CWE-284) in the getStationMacByIp function of TOTOLINK T6 wireless router firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint. A successful request reveals the MAC address of a client device on the network, an information leak with a high confidentiality impact (CVSS 7.5) that could support further reconnaissance of the local network. Only TOTOLINK T6 routers running the documented firmware version are confirmed affected. Exploitation has not been reported: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.4% probability of exploitation in the next 30 days.
What to do: Check whether your TOTOLINK T6 is running firmware 4.1.5cu.748_B20211015 and, until a patched firmware is released, avoid exposing the router's web management interface (the /cgi-bin/cstecgi.cgi endpoint) to untrusted networks or the WAN side. Restricting management access to trusted LAN clients and monitoring TOTOLINK for an official firmware update are reasonable interim mitigations.
| TOTOLINK T6 wireless router | 4.1.5cu.748_B20211015 (the only version documented in the advisory; other firmware versions are not confirmed affected) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.