CVE-2026-51636
largeUnauthenticated Wi-Fi ACL rule disclosure in TOTOLINK T6 router
CVE-2026-51636 is an improper access-control flaw (CWE-284) in the getWiFiAclRules function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi web management endpoint, with no credentials or user interaction required. On success, the attacker can read the router's Wi-Fi access-control list — the configured rules describing which client devices are allowed or blocked from the wireless network — which the 9.1 CVSS score reflects as a high-impact information disclosure. Administrators and owners of TOTOLINK T6 routers running the named firmware are affected, especially where the web interface is reachable from the internet or from untrusted networks. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.4% chance of exploitation within 30 days, so no exploitation is known as of publication.
What to do: Check the running firmware version on any TOTOLINK T6 (visible on the router's status page) and, because the advisory names no fixed build, monitor TOTOLINK's support site for a patched release before upgrading. As interim mitigation, do not expose the router's web administration interface to the WAN (disable remote management or restrict it to the trusted LAN) so unauthenticated POSTs to /cgi-bin/cstecgi.cgi cannot reach the device. Note that the ACL contents returned to an attacker can reveal information about permitted and blocked client devices, so review those rules for anything sensitive after patching.
| TOTOLINK T6 router | firmware 4.1.5cu.748_B20211015 (the only version named in the advisory; other builds may also be affected but are not confirmed in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.