ZeroHour

CVE-2026-51625

niche

Unauthenticated Wi-Fi credential disclosure in TOTOLINK T6 router

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51625 is an incorrect access control flaw (CWE-284) in the getWiFiEasyCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's management endpoint /cgi-bin/cstecgi.cgi, without needing any credentials or user interaction. Successful exploitation discloses sensitive wireless configuration data, including the network SSIDs and the Wi-Fi keys (pre-shared passwords). Any TOTOLINK T6 device on this firmware is affected, and exposure is highest when the router's web management interface is reachable from the WAN/internet; an attacker who learns the Wi-Fi keys could join the wireless network. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.4%, so no in-the-wild exploitation is known.

What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and contact TOTOLINK support for a corrected firmware, as no fixed version is specified in the available data. As a mitigation, do not expose the router's management interface (port 80/443 on the WAN side) or /cgi-bin/cstecgi.cgi to the internet, and restrict remote administration. If the device may have been exposed, consider rotating the Wi-Fi passwords, since SSIDs and Wi-Fi keys are what the flaw discloses.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (firmware confirmed affected; other version ranges not specified in available data)
Estimated exposure
nichelikely tens of thousands of T6 units deployed (single consumer router model; internet-exposed subset unknown) — Estimate is based on TOTOLINK being a budget consumer-router brand with distribution concentrated in Asia, the Middle East and Latin America, and public internet scans historically showing thousands to tens of thousands of TOTOLINK devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.