ZeroHour

CVE-2026-51624

Unauthenticated client MAC disclosure in TOTOLINK T6 router firmware

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51624 is an improper access-control flaw (CWE-284) in the getStationMacByIp function of TOTOLINK T6 wireless router firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint. A successful request reveals the MAC address of a client device on the network, an information leak with a high confidentiality impact (CVSS 7.5) that could support further reconnaissance of the local network. Only TOTOLINK T6 routers running the documented firmware version are confirmed affected. Exploitation has not been reported: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.4% probability of exploitation in the next 30 days.

What to do: Check whether your TOTOLINK T6 is running firmware 4.1.5cu.748_B20211015 and, until a patched firmware is released, avoid exposing the router's web management interface (the /cgi-bin/cstecgi.cgi endpoint) to untrusted networks or the WAN side. Restricting management access to trusted LAN clients and monitoring TOTOLINK for an official firmware update are reasonable interim mitigations.

Affected
TOTOLINK T6 wireless router4.1.5cu.748_B20211015 (the only version documented in the advisory; other firmware versions are not confirmed affected)
Estimated exposure
unknown (no public install, market-share, or internet-exposure counts available for the TOTOLINK T6 model) — The advisory data contains no active-install, market-share, or scan-based exposure counts for this specific router model, and no public scan statistics for TOTOLINK T6 devices were provided.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.